Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized modification of displayed content in Performance Management Application, SAP security note 2131081

SAP Note 2131081SAP Security NoteHigh priority

SAP security note 2131081, "Unauthorized modification of displayed content in Performance Management Application", is a note released on 22.05.2015. Below are the symptom and SAP recommended solution.

ComponentBusiness intelligence solutions > Business intelligence platform > BI Workspaces (Dashboard Builder)
PriorityCorrection with high priority
TypeSAP Security Note
Version5
StatusReleased for Customer
Released on22.05.2015

Description

Symptom

Performance Management Application can be abused by an attacker, allowing them to modify displayed application content without authorization, and potentially obtain authentication information from other legitimate users.

Solution

This issue has been resolved. Please refer to the Support Packages and Patches section to apply the necessary updates.

Reason and prerequisites

The intermediateSaveInfoView page within the Performance Management Application does not sufficiently encode OUTPUT parameters, resulting in a reflected cross-site scripting (XSS) vulnerability. An attacker can exploit this to non-permanently deface or modify displayed content on the website or steal users’ authentication information.

CVSS

Score 4.3 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

References

Full note on SAP: SAP Support Launchpad note 2131081

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More