SAP security note 1998770, “Unauthorized change of stored content through manipulation of BC-BMT-WFM”, is a program error note released on 03.07.2014. Below is the security information published by SAP for this note.
Description
Symptom
An attacker can cause a stored cross-site scripting problem by manipulating BC-BMT-WFM.
Reason and prerequisites
Stored cross-site scripting can be used to permanently modify the displayed content of a Web site, allowing the attacker to embed content that is then generated and displayed automatically, without having to target victims individually.
Solution
Following the implementation of the attached corrections or the import of the corresponding Support Packages, BC-BMT-WFM uses the virus scan profile that is active for the SAPoffice environment. With regard to this, see the profile set in the parameter SO_VSI_PROFILE in the table SXPARAMS.
Additional information
- Type: SAP Security Note
- Version: 1
- Recency: New
- Language: English
- Category: Program error
- Priority: Correction with medium priority
- Status: Released for Customer
- Released On: 03.07.2014
- Component: Basis Components > Business Management > Business Workflow
Full note on SAP: SAP Support Launchpad note 1998770
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
