SAP security note 1603081, "Unauthorized modification of displayed content in ISA-AUC". Below are the symptom and SAP recommended solution.
Description
Symptom
- Unauthorized modification of displayed content.
- Potential theft of authentication data via XSS attacks.
Solution
This note provides Java corrections for E-Commerce and Web Channel.
- Software Component: SAP-SHRWEB
- Changed File: shops.jsp
- Apply the Support Package patch level attached to this note.
For more information on applying Java patches, refer to Note 877887. See Note 1546959 for information about the patch strategy.
Reason and prerequisites
Insufficient encoding of output parameters on the shop list page within CRM-ISA-AUC, leading to a reflected XSS vulnerability.
References
Full note on SAP: SAP Support Launchpad note 1603081
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
