SAP security note 2189174, “Unauthorized Modification of Displayed Content in Message Server”, is a note released on March 8, 2016. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An attacker can abuse the message server to:
- Modify displayed application content without authorization.
- Obtain authentication information from other legitimate users, potentially leading to session hijacking and impersonation.
Solution
Apply the kernel patch level specified in SAP Security Note 2189174. Ensure that your system is updated to at least the recommended patch levels to mitigate the vulnerability.
Reason and prerequisites
An HTTP or HTTPS port must be configured for the message server. Within HTTP(S) message processing, the message server must not sufficiently encode output parameters, leading to the XSS issue.
Affected components
- KRNL32NUC
- KRNL32UC
- KRNL64NUC
- KRNL64UC
- KERNEL
Versions affected: various versions across 7.21, 7.22, 7.41, 7.42, 7.43, 7.44, and 7.45 for both 32-bit and 64-bit systems.
Full note on SAP: SAP Support Launchpad note 2189174
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
