SAP Security Note
High priority
SAP security note 1494102, "Unauthorized modification of displayed content ICCMP_SSC_LL", is a program error note released on 14.12.2010. Below are the symptom and SAP recommended solution.
Description
Symptom
The ICCMP_SSC_LL BSP application can be exploited by a malicious user to modify displayed application content without authorization and potentially obtain authentication information from other legitimate users.
Solution
Apply the provided correction or install the relevant support package.
Reason and prerequisites
The BSP page ICCMP_SSC_LL\Repository.xml does not sufficiently encode input parameters, leading to a reflected cross-site scripting vulnerability. This vulnerability allows attackers to:
- Deface or modify displayed content: Temporarily alter the appearance or content of the web application.
- Steal authentication information: Access sensitive data related to user sessions, enabling impersonation of legitimate users and unauthorized access to information.
Full note on SAP: SAP Support Launchpad note 1494102
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
