SAP Security Note
High priority
SAP security note 1674713, "Unauthorized modification in ITS services", was released on 08.05.2012. Below are the symptom and SAP recommended solution.
Description
Symptom
The SRM-EBP-BID component can be exploited by a malicious user to modify displayed application content without authorization. This vulnerability may allow the theft of authentication information from other legitimate users.
Solution
Apply this SAP Security Note or import the changes via the relevant support package. Additionally, ensure that the corrections from SAP Notes 1621946 and 1488500 are implemented to fully mitigate the vulnerability.
Reason and prerequisites
ITS Services [BBPAT04, BBPATTRMAINT, BBPADM_COCKPIT, BBPWEBMONITOR, BBPWEBMON_SEP, BBP_CTR_MON, BBPHELP, BBPOR01, BBPOR02, BBPPS01, and PSSRM_TNDR (only in SRM 7.02)] within SRM-EBP-BID do not sufficiently encode OUTPUT parameters, resulting in a cross-site scripting (XSS) issue. This vulnerability can be exploited to steal a user’s authentication information, allowing an attacker to impersonate the user and access data with the same privileges.
If an administrator is impersonated, the security of the entire application may be fully compromised.
References
- SAP Note 1621946 – ITS: updated XSS-escaping functions
- SAP Note 1488500 – ITS: automatically escape context fields in output
Full note on SAP: SAP Support Launchpad note 1674713
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




