SAP Security Note
High priority
SAP security note 1526168, "Unauthorized modification of contents displayed in ICF", is released on 13.09.2011. Below are the symptom and SAP recommended solution.
Description
Symptom
Data in the Internet Communication Framework (ICF) can be abused by a malicious user, allowing unauthorized modification of displayed application content and potential theft of authentication information from other legitimate users.
API interfaces within the ICF do not sufficiently encode input/output parameters, resulting in a reflected cross-site scripting (XSS) vulnerability. This can be exploited to deface or modify displayed content and steal users’ authentication data, leading to impersonation and unauthorized access. If an administrator is impersonated, the security of the application may be fully compromised.
Solution
Implement the specified source code corrections by following the provided correction instructions.
References
Full note on SAP: SAP Support Launchpad note 1526168
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
