Medium priority
SAP security note 2079002, "Unauthorized modification of displayed content in logon application", released on July 27, 2015. Below are the symptom and SAP recommended solution.
Description
Symptom
SAP Security Note 2079002 addresses a reflected Cross-Site Scripting (XSS) vulnerability in the AS Java logon application. This vulnerability allows an attacker to modify displayed application content without authorization and potentially steal authentication information from other legitimate users.
Solution
To mitigate this vulnerability, apply the corrective measures outlined in the "Validity" and "Support Package Patch Level" sections of SAP Security Note 2079002. Ensure that your system is updated to the recommended support package levels to protect against this security issue.
Reason and prerequisites
Exploiting this vulnerability allows attackers to:
- Modify content displayed in the logon application.
- Potentially obtain authentication information from other users.
- Impersonate users, including administrators, leading to full compromise of application security.
CVSS
Score 5.8 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:P
Full note on SAP: SAP Support Launchpad note 2079002
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
