High priority
SAP security note 2090013, "Unauthorized modification of displayed content in NetWeaver logon application", is a program error note released on 11.08.2015. Below are the symptom and SAP recommended solution.
Description
Symptom
The NetWeaver logon application can be abused by an attacker, allowing them to modify displayed application content without authorization and potentially obtain authentication information from other legitimate users.
Solution
Apply the latest patches relevant to the release and support package level of your AS Java as described in the "SP Patch Level" section of the note.
Reason and prerequisites
The logon pages within the NetWeaver logon application do not sufficiently encode input parameters, resulting in a reflected cross-site scripting (XSS) vulnerability. This can be exploited to deface or modify displayed content and steal user authentication information, potentially allowing attackers to impersonate users with the same rights.
CVSS
Score 4.3 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N
Full note on SAP: SAP Support Launchpad note 2090013
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
