SAP Security Note
High priority
SAP security note 1482118, "Unauthorized change to data displayed in BPS planning", is a program error note released on 14.06.2011. Below are the symptom and SAP recommended solution.
Description
Symptom
An attacker can change another user without authorization by manipulating data displayed in Business Planning and Simulation (BPS) planning. This can potentially allow access to the victim’s authentication data.
Reflected Cross-Site Scripting (XSS) vulnerability is triggered due to inadequate source code implementation for outputting data via a web page in BPS planning. An attacker can exploit this to manipulate web page contents by crafting a manipulated link. This can lead to stealing logon information from the victim’s current session, enabling the attacker to impersonate the victim with the same access rights. If the targeted user has administrative privileges, the entire application data may be compromised.
Solution
To address this vulnerability, apply the appropriate Support Package for your SAP NetWeaver BW version:
- SAP NetWeaver BW 7.00: Import Support Package 25 (SAPKW70025) once Note 1468668 is released.
- SAP NetWeaver BW 7.01 (Enhancement Package 1): Import Support Package 08 (SAPKW70108) once Note 1471463 is released.
- SAP NetWeaver BW 7.02 (Enhancement Package 2): Import Support Package 06 (SAPKW70206) once Note 1450990 is released.
- SAP NetWeaver BW 7.11: Import Support Package 05 (SAPKW71105) once Note 1392433 is released.
Urgent Cases: Implement the correction instructions as an advance correction by following the steps in Note 875986, which provides information about transaction SNOTE. Preliminary versions of the correction instructions may be available before the Support Package release; look for the "Preliminary version" label in the note’s short text.
References
- Update #1 for Security Note 1482118 (1599806)
- Automatic checks for security notes using RSECNOTE (outdated) (888889)
Full note on SAP: SAP Support Launchpad note 1482118
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



