Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized modification of stored content in Payroll Data Source Framework, SAP security note 1987210

SAP Note 1987210
Medium priority

SAP security note 1987210, "Unauthorized modification of stored content in Payroll Data Source Framework", is a note released on 05.03.2014. Below are the symptom, SAP recommended solution and the affected software components.

ComponentPayroll > Payroll: General Parts > Obsolete – please use PY-LOC* components instead
PriorityCorrection with medium priority
TypeSAP Security Note
StatusReleased for Customer
Released on05.03.2014

Description

Symptom

The Payroll Data Source Framework can be abused by an attacker to modify application content, persist the changes without authorization, and potentially obtain authentication information from other legitimate users.

This vulnerability allows for stored cross-site scripting (XSS), enabling attackers to:

  • Steal user authentication information.
  • Impersonate users.
  • Potentially compromise the security of the entire application if an administrator is targeted.

Solution

Apply the following correction instructions to resolve the issue.

Reason and prerequisites

The OData service PYD_FRW provided by the Payroll Data Source Framework results in a stored XSS issue. This service is only active if the Business Function HCM_LOC_CI_62 ("Payroll Data Source Framework") is enabled.

Affected components

  • SAP_HRRXX from version 608 onwards

Full note on SAP: SAP Support Launchpad note 1987210

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More