Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized changes of stored contents(agency collections), SAP security note 1472395

SAP Note 1472395
SAP Security Note
High priority

SAP security note 1472395, "Unauthorized changes of stored contents (agency collections)", is a program error note released on 09.11.2010. Below are the symptom, SAP recommended solution and the affected software components.

ComponentFinancial Services > Collections and Disbursements (FS-CD)
CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
Version6
StatusReleased for Customer
Released on09.11.2010
LanguageEnglish

Description

Symptom

This note is relevant only if you use the application component FS-CD (software component INSURANCE) and the BSP applications of the Italian agency collections within this application component. If you do not use these components, you are not affected by the problem and you do not have to implement this note.

By manipulating the agency collections, an attacker can change the displayed data of another user without having the relevant authorization. The attacker can also save the data that has been changed and may be able to access the authentication data of the user.

Solution

Implement this note or import the relevant Support Package. In addition, implement Note 1480715.

Reason and prerequisites

Since there is no sufficient input validation using the component FSCDITAGCY_START, a permanent cross-site scripting may be triggered. As a result, an attacker can store manipulated content on a server. This content is displayed automatically for a victim and is interpreted by the victim’s browser. This enables the attacker to obtain the information of a user. The attacker can use this information so that the application assumes that the attacker has the relevant authorization. As a result, the attacker can use the application with the authorizations of the victim. If a user with administration authorizations falls victim to an attack, all of the data of the application may be compromised.

This document is causing side effects with Note 1480715.

References

Affected components

  • INSURANCE 472
  • INSURANCE 600
  • INSURANCE 602
  • INSURANCE 603
  • INSURANCE 604
  • INSURANCE 605

Full note on SAP: SAP Support Launchpad note 1472395

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More