Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized modification of displayed content in message server, SAP security note 2189174

SAP Note 2189174

SAP security note 2189174, “Unauthorized Modification of Displayed Content in Message Server”, is a note released on March 8, 2016. Below are the symptom, SAP recommended solution and the affected software components.

StatusReleased for Customer
Released onMarch 8, 2016

Description

Symptom

An attacker can abuse the message server to:

  • Modify displayed application content without authorization.
  • Obtain authentication information from other legitimate users, potentially leading to session hijacking and impersonation.

Solution

Apply the kernel patch level specified in SAP Security Note 2189174. Ensure that your system is updated to at least the recommended patch levels to mitigate the vulnerability.

Reason and prerequisites

An HTTP or HTTPS port must be configured for the message server. Within HTTP(S) message processing, the message server must not sufficiently encode output parameters, leading to the XSS issue.

Affected components

  • KRNL32NUC
  • KRNL32UC
  • KRNL64NUC
  • KRNL64UC
  • KERNEL

Versions affected: various versions across 7.21, 7.22, 7.41, 7.42, 7.43, 7.44, and 7.45 for both 32-bit and 64-bit systems.

Full note on SAP: SAP Support Launchpad note 2189174

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More