SAP security note 1417568, "Unauthorized Change of Contents in CERTREQ and CERTMAP". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An attacker can manipulate the BSP applications CERTREQ and CERTMAP to change displayed data of another user without authorization and may access the authorization data of this user.
Solution
Implement the attached corrections provided in this security note. For Release 6.40, also apply the corrections from Note 1475840 and the kernel patch from Note 1468542. If the BSP applications CERTREQ and CERTMAP are not required, deactivate them using transaction SICF. Additionally, ensure that the ITS services CERTREQ and CERTMAP are deactivated in each case.
Reason and prerequisites
Due to inadequate input validation in the BSP applications CERTREQ and CERTMAP, a reflected cross-site scripting (XSS) vulnerability can be triggered. This allows the content of a web page to be manipulated when a crafted link is accessed. An attacker can exploit this to steal the logon information of the current session, impersonate the victim, and access the application with the victim’s privileges. If the victim has administrative rights, all application data may be compromised.
References
- Downporting security functions in CL_HTTP_UTILITY (Note 1475840)
- Collective correction for BSP application CERTREQ (Note 1142365)
Affected components
- SAP_BASIS 6.40
- SAP_BASIS 7.00 to 7.02
- SAP_BASIS 7.10 to 7.20
Full note on SAP: SAP Support Launchpad note 1417568
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
