SAP Security Note
Medium priority
SAP security note 1749111, “Unauthorized modification of displayed content in BOE”, is a note released on April 9, 2013. Below are the symptom and SAP recommended solution.
Description
Symptom
BusinessObjects BI Launch Pad can be abused by an attacker, allowing them to modify displayed application content without authorization, and to potentially obtain authentication information from other legitimate users.
Solution
Apply one of the following based on your installed version:
- SAP BusinessObjects BI platform 4 (XI4.0) SP2 FixPack20 (2.20)
- SAP BusinessObjects BI platform 4 (XI4.0) FeaturePack3 FixPack 9
- SAP BusinessObjects BI platform 4 (XI4.0) SP4 FixPack 3
- SAP BusinessObjects BI platform 4 (XI4.0) SP5 and higher versions
Reason and prerequisites
Pages within BusinessObjects BI Launch Pad do not sufficiently encode input parameters, resulting in a reflected cross-site scripting (XSS) issue. This vulnerability can be exploited to deface or modify displayed content and steal user authentication information, potentially allowing attackers to impersonate users or administrators.
CVSS
Score 3.5 Vector: AV:N/AC:M/AU:S/C:P/I:N/A:N
Full note on SAP: SAP Support Launchpad note 1749111
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



