SAP Security Note
SAP security note 1762486, “Unauthorized modification of displayed content in BOE”, is a note released on April 9, 2013. Below are the symptom and SAP recommended solution.
Description
Symptom
SAP Business Intelligence 4 can be abused by an attacker, allowing them to modify displayed application content without authorization, and potentially obtain authentication information from other legitimate users.
Solution
Customers are advised to install patch 2.16 or Service Pack 4 (SP4) for BI4 to address this vulnerability.
Reason and prerequisites
Pages within SAP BusinessObjects Enterprise do not sufficiently encode input parameters, resulting in a reflected cross-site scripting vulnerability. This can allow an attacker to non-permanently deface or modify displayed content on a website. Additionally, stolen authentication information can be used to impersonate users, potentially compromising the security of the entire application if an administrator is targeted.
An attacker exploiting this vulnerability can:
- Modify displayed content without authorization.
- Steal authentication information to impersonate legitimate users.
- Potentially gain administrative access, compromising the entire application.
CVSS
Score 4.3 Vector: AV:N/AC:M/AU:N/C:N/I:P/A:N
Full note on SAP: SAP Support Launchpad note 1762486
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
