Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized change to data displayed in BPS planning, SAP security note 1482118

SAP Note 1482118
SAP Security Note
High priority

SAP security note 1482118, "Unauthorized change to data displayed in BPS planning", is a program error note released on 14.06.2011. Below are the symptom and SAP recommended solution.

ComponentSAP Business Warehouse > Planning > Business Planning and Simulation (BW-PLA-BPS)
CategoryProgram error
PriorityHigh priority
TypeSAP Security Note
Version8
StatusReleased for Customer
Released on14.06.2011
LanguageEnglish

Description

Symptom

An attacker can change another user without authorization by manipulating data displayed in Business Planning and Simulation (BPS) planning. This can potentially allow access to the victim’s authentication data.

Reflected Cross-Site Scripting (XSS) vulnerability is triggered due to inadequate source code implementation for outputting data via a web page in BPS planning. An attacker can exploit this to manipulate web page contents by crafting a manipulated link. This can lead to stealing logon information from the victim’s current session, enabling the attacker to impersonate the victim with the same access rights. If the targeted user has administrative privileges, the entire application data may be compromised.

Solution

To address this vulnerability, apply the appropriate Support Package for your SAP NetWeaver BW version:

Urgent Cases: Implement the correction instructions as an advance correction by following the steps in Note 875986, which provides information about transaction SNOTE. Preliminary versions of the correction instructions may be available before the Support Package release; look for the "Preliminary version" label in the note’s short text.

References

Full note on SAP: SAP Support Launchpad note 1482118

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More