SAP security note 1483548, “Modification of displayed content in login screen”, is a program error note released on 19.06.2014. Below is the security information published by SAP for this note.
Description
#### Symptom A malicious user can trigger functionality in the system login for form fields "sap-client" and "sap-urlscheme".
#### Other Terms Cross-Site Request Forgery (XSRF), system login, SICF
#### Reason and Prerequisites
- The form field "sap-client" must not be filled with more than 3 digits for SAP clients.
- The validity of the form field "sap-urlscheme" will be checked for input values.
Solution
Please import the ABAP correction in the Basis support package.
Affected components
- SAP_BASIS versions:
- 640
- 700 to 702
- 710 to 730
Full note on SAP: SAP Support Launchpad note 1483548
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



