Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

ROS Unauthorized modification in BSP application, SAP security note 1679689

SAP Note 1679689

SAP security note 1679689, "ROS: Unauthorized modification in BSP application". Below are the symptom and SAP recommended solution.

Description

Symptom

The SRM-ROS application component is vulnerable to unauthorized modifications in BSP applications. Specifically, the ROS_SELF_REG and ROS_SELF_EDIT functions do not adequately encode OUTPUT parameters, leading to a Cross-Site Scripting (XSS) vulnerability. This flaw allows malicious users to alter displayed application content without proper authorization and potentially steal authentication information from legitimate users. If an attacker impersonates an administrator, the entire application’s security can be compromised.

Solution

To address this vulnerability, implement the relevant support packages or apply the provided correction instructions.

Full note on SAP: SAP Support Launchpad note 1679689

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More