Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized change of displayed contents, SAP security note 1422572

SAP Note 1422572

SAP security note 1422572, "Unauthorized change of displayed contents". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

An attacker can manipulate certain input parameters in the Web service infrastructure to change the displayed data of another user without authorization and may access the authorization data of this user.

Solution

Import the relevant Support Package or implement the correction instructions. You can download the necessary Support Packages here.

Reason and prerequisites

Since output is not sufficiently coded in the class CL_HTTP_EXT_FORMTORFC, reflected cross-site scripting may be triggered. As a result, the content of a Web page can be manipulated when a manipulated link is called, for example.

An attacker can use reflected cross-site scripting to steal the logon information of the current session of the victim. The attacker can then use this information to pretend to the server that they are the victim and can use the application with the same rights as the user who was attacked.

If the target of the attack is a user with administrative rights, all of the application data may be compromised as a result.

References

Affected components

  • SAP_BASIS versions 620 to 720

Full note on SAP: SAP Support Launchpad note 1422572

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More