Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized modification of stored content in EPCF Loader Tester, SAP security note 2228405

SAP Note 2228405

SAP security note 2228405, "Unauthorized modification of stored content in EPCF Loader Tester". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

The EPCF Loader Tester can be abused by an attacker, allowing unauthorized modification of application content, persistence of the modified content, and potential retrieval of authentication information from legitimate users.

Solution

Apply the latest patches attached to this note to mitigate the vulnerability.

Reason and prerequisites

The EPCF Loader Tester results in a stored cross-site scripting (XSS) vulnerability. This can be exploited to permanently modify displayed content on a website, allowing attackers to embed content that is rendered automatically without targeting victims individually. Additionally, stored XSS can be used to steal another user’s authentication information, such as session data, which can be leveraged to impersonate the user and access information with their privileges. If an administrator is impersonated, the security of the application may be fully compromised.

CVSS

Score 3.5 / 10 Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

References

Affected components

  • EP-PSERV 7.00 – 7.02
  • EP-RUNTIME 7.10 – 7.50
  • PORTAL PLATFORM 6.0_640
  • PORTAL 7.00 – 7.02

Full note on SAP: SAP Support Launchpad note 2228405

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More