Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized modification of displayed content in logon application, SAP security note 2079002

SAP Note 2079002
Medium priority

SAP security note 2079002, "Unauthorized modification of displayed content in logon application", released on July 27, 2015. Below are the symptom and SAP recommended solution.

ComponentBC-JAS-SEC-LGN (Logon, SSO)
PriorityCorrection with medium priority
StatusReleased for Customer
Released onJuly 27, 2015

Description

Symptom

SAP Security Note 2079002 addresses a reflected Cross-Site Scripting (XSS) vulnerability in the AS Java logon application. This vulnerability allows an attacker to modify displayed application content without authorization and potentially steal authentication information from other legitimate users.

Solution

To mitigate this vulnerability, apply the corrective measures outlined in the "Validity" and "Support Package Patch Level" sections of SAP Security Note 2079002. Ensure that your system is updated to the recommended support package levels to protect against this security issue.

Reason and prerequisites

Exploiting this vulnerability allows attackers to:

  • Modify content displayed in the logon application.
  • Potentially obtain authentication information from other users.
  • Impersonate users, including administrators, leading to full compromise of application security.

CVSS

Score 5.8 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:P

Full note on SAP: SAP Support Launchpad note 2079002

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More