SAP security note 1567630, "Unauthorized modification of displayed content in BC-DOC-TTL", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
This SAP Security Note addresses a reflected Cross Site Scripting (XSS) vulnerability in the translation tools of BC-DOC-TTL. A malicious user could exploit this vulnerability to modify displayed application content without authorization or steal authentication information from other users.
The translation tools can be abused by a malicious user, allowing unauthorized modification of displayed content and potential theft of authentication information from legitimate users.
Solution
Implement the changes outlined in the attached correction instructions for your system. This note disables obsolete code, and no additional testing is required post-implementation.
Reason and prerequisites
Pages within the translation tools do not sufficiently encode input parameters, resulting in a reflected XSS issue. This can be exploited to deface or modify web content temporarily and steal user session data, potentially leading to full security compromises if an administrator’s credentials are obtained.
References
Affected components
- SAP_BASIS: From 620 to 640
- SAP_BASIS: From 700 to 702
- SAP_BASIS: From 710 to 730
- SAP_BASIS: From 72L to 72L
Full note on SAP: SAP Support Launchpad note 1567630
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
