SAP Security Note
Medium priority
SAP security note 2095236, "Unauthorized modification of displayed content in Web interface of Web Intelligence document", was released on February 10, 2015. Below are the symptom and SAP recommended solution.
Description
Symptom
The Web/HTML interface of a Web Intelligence document can be exploited by an attacker to modify displayed application content without authorization. This vulnerability may allow an attacker to obtain authentication information from other legitimate users, potentially leading to impersonation and unauthorized access.
Solution
To address this vulnerability, update your SBOP BI Platform Server and Client installations to a Support Package, Patch, or Release where the issue is resolved.
CVSS
Score 3.5 Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N
References
- SAP Note 2164805: View or edit the Web Intelligence document in DHTML mode, the garbage code is displayed for the name of "Favorites Folder" and "Public Folders"
Full note on SAP: SAP Support Launchpad note 2095236
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



