Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized modification of displayed content in CEC-MKT-CEI-BF / CA-CEI-ADT, SAP security note 2120721

SAP Note 2120721
SAP Security Note
Medium priority

SAP security note 2120721, "Unauthorized modification of displayed content in CEC-MKT-CEI-BF / CA-CEI-ADT", is a note released on June 10, 2015. Below are the symptom and SAP recommended solution.

ComponentCustomer Engagement and Commerce > Marketing > Basic Functions (CEC-MKT-BF)
PriorityCorrection with medium priority
TypeSAP Security Note
Version4
StatusReleased for Customer
Released onJune 10, 2015

Description

Symptom

CA-CEI-ADT can be abused by an attacker, allowing them to modify displayed application content without authorization, and to potentially obtain authentication information from other legitimate users.

Solution

Implement the attached correction instructions to mitigate this vulnerability.

Reason and prerequisites

CA-CEI-ADT results in a reflected cross-site scripting (XSS) issue. This vulnerability can be exploited to non-permanently deface or modify displayed content on a website and steal user authentication information. An attacker may use this data to impersonate users, including administrators, thereby compromising the security of the application.

Prerequisite: SAPUI5 1.26.3 must be installed before applying this note.

Full note on SAP: SAP Support Launchpad note 2120721

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More