SAP security note 1678243, "Unauthorized modification of BSP in Webdocuments (2)", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Unauthorized modification of application content in Webdocuments.
Potential theft of user authentication information.
Possibility of impersonating users, including administrators.
Solution
Apply SAP Security Note 1678243 or import the necessary changes via the relevant support package. This note is specifically applicable to the Ehp6 release. Ensure that the following prerequisite notes are also applied based on your current release:
- 1420256 – Unauthorized modification of displayed content in Webdocs
- 1505976 – Webdocs: Unauthorized Content Modification & Session Handling
- 1509753 – Webdocs: XSRF Protection for BSP Application WebDocuments
- 1582867 – Security options (XSS) for ESCAPE
- 1582870 – ABAP XSS Escaping Support
- 1670098 – Unauthorized modification of BSP in Webdocuments
Affected components
- EA-APPL 606
Full note on SAP: SAP Support Launchpad note 1678243
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




