Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized modification of stored content in Portal Page Builder, SAP security note 2219896

SAP Note 2219896
SAP Security Note
Medium priority

SAP security note 2219896, “Unauthorized modification of stored content in Portal Page Builder”, is a note released on 08.03.2016. Below are the symptom and SAP recommended solution.

ComponentEnterprise Portal > SAP Enterprise Portal (On Premise) > Page Builder > Portal Runtime
PriorityCorrection with medium priority
TypeSAP Security Note
Version6
StatusReleased for Customer
Released on08.03.2016

Description

Symptom

Portal Page Builder test component can be abused by an attacker, allowing them to modify application content and potentially obtain authentication information from other legitimate users.

Stored cross-site scripting (XSS) vulnerability in the Page Builder test component. This flaw allows attackers to permanently modify displayed content on a website, embed malicious content that executes automatically, and steal authentication information from users. Such an attack can lead to impersonation of users, including administrators, thereby compromising the security of the application.

Solution

Check the appropriate Support Package (SP) and Patch level that addresses this issue under the “Support Packages & Patches” tab within this SAP Note.

CVSS

Score 5.4 / 10 Vector: AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

References

  • 2110834: Central Note for Portal Platform in SAP NW7.0 EhP1 SP18
  • 2110779: Central Note for Portal Platform in SAP NW7.0 SP33

Full note on SAP: SAP Support Launchpad note 2219896

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More