SAP Security Note
Medium priority
SAP security note 2219896, “Unauthorized modification of stored content in Portal Page Builder”, is a note released on 08.03.2016. Below are the symptom and SAP recommended solution.
Description
Symptom
Portal Page Builder test component can be abused by an attacker, allowing them to modify application content and potentially obtain authentication information from other legitimate users.
Stored cross-site scripting (XSS) vulnerability in the Page Builder test component. This flaw allows attackers to permanently modify displayed content on a website, embed malicious content that executes automatically, and steal authentication information from users. Such an attack can lead to impersonation of users, including administrators, thereby compromising the security of the application.
Solution
Check the appropriate Support Package (SP) and Patch level that addresses this issue under the “Support Packages & Patches” tab within this SAP Note.
CVSS
Score 5.4 / 10 Vector: AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
References
- 2110834: Central Note for Portal Platform in SAP NW7.0 EhP1 SP18
- 2110779: Central Note for Portal Platform in SAP NW7.0 SP33
Full note on SAP: SAP Support Launchpad note 2219896
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
