High priority
SAP security note 1676722, “Unauthorized modification of BSP in Webdocuments”, released on 08.05.2012. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Malicious users can unauthorizedly modify Webdocuments content and potentially obtain authentication information from other users.
Solution
Apply SAP Security Note 1676722 or import the necessary changes via the relevant support packages.
Reason and prerequisites
The Webdynpro class DPWTY_CL_UI_CLAIM_DETAIL does not properly encode output parameters, leading to a cross-site scripting (XSS) vulnerability. This can be exploited to steal authentication data, impersonate users, and compromise overall application security, especially if administrative accounts are targeted.
References
Affected components
- Industry-Specific Components > Automotive > Dealer Portal > Warranty Online WebFrontend (IS-A-DP-WTY)
Full note on SAP: SAP Support Launchpad note 1676722
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



