SAP Security Note
Medium priority
SAP security note 2120721, "Unauthorized modification of displayed content in CEC-MKT-CEI-BF / CA-CEI-ADT", is a note released on June 10, 2015. Below are the symptom and SAP recommended solution.
Description
Symptom
CA-CEI-ADT can be abused by an attacker, allowing them to modify displayed application content without authorization, and to potentially obtain authentication information from other legitimate users.
Solution
Implement the attached correction instructions to mitigate this vulnerability.
Reason and prerequisites
CA-CEI-ADT results in a reflected cross-site scripting (XSS) issue. This vulnerability can be exploited to non-permanently deface or modify displayed content on a website and steal user authentication information. An attacker may use this data to impersonate users, including administrators, thereby compromising the security of the application.
Prerequisite: SAPUI5 1.26.3 must be installed before applying this note.
Full note on SAP: SAP Support Launchpad note 2120721
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




