SAP Security Note
High priority
SAP security note 1520314, "Unauthorized modification of displayed content in BC-SRV-KPR", was released on 12.01.2011. Below are the symptom and SAP recommended solution.
Description
Symptom
The BC-SRV-KPR-CMS can be exploited by malicious users to modify displayed application content without authorization. This vulnerability allows attackers to potentially obtain authentication information from other legitimate users.
Solution
To address this vulnerability, implement this SAP Note or import the relevant support package.
Reason and prerequisites
Pages within the BC-SRV-KPR-CMS do not sufficiently encode output parameters, resulting in a reflected Cross Site Scripting (XSS) issue. A reflected XSS attack can be used to non-permanently deface or modify displayed content on a website. Additionally, attackers can steal another user’s authentication information, such as data related to their current session, which may be used to impersonate the user and access information with the same privileges. If an administrator is impersonated, it could lead to a full compromise of the application’s security.
Full note on SAP: SAP Support Launchpad note 1520314
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
