SAP security note 1676753, “Unauthorized modification of BSP in Webdocuments”, is published by SAP for the affected component listed below. The description reproduces the information SAP released for this note.
Description
The Webdocuments can be abused by malicious users allowing them to modify displayed application content without authorization, and to potentially obtain authentification information from other legitimate users.
CVSS
Score 0
Affected components
- ECC-DIMP | 604 | 604
- ECC-DIMP | 605 | 605
- ECC-DIMP | 606 | 606
- ECC-DIMP 606 | SAPK-60603INECCDIMP
- ECC-DIMP 604 | SAPK-60412INECCDIMP
- ECC-DIMP 605 | SAPK-60509INECCDIMP
Full note on SAP: SAP Support Launchpad note 1676753
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
