Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized modification of displayed content in BC-SRV-KPR, SAP security note 1520314

SAP Note 1520314
SAP Security Note
High priority

SAP security note 1520314, "Unauthorized modification of displayed content in BC-SRV-KPR", was released on 12.01.2011. Below are the symptom and SAP recommended solution.

ComponentBasis Services/Communication Interfaces > Knowledge Provider (BC-SRV-KPR)
PriorityCorrection with high priority
TypeSAP Security Note
StatusReleased for Customer
Released on12.01.2011

Description

Symptom

The BC-SRV-KPR-CMS can be exploited by malicious users to modify displayed application content without authorization. This vulnerability allows attackers to potentially obtain authentication information from other legitimate users.

Solution

To address this vulnerability, implement this SAP Note or import the relevant support package.

Reason and prerequisites

Pages within the BC-SRV-KPR-CMS do not sufficiently encode output parameters, resulting in a reflected Cross Site Scripting (XSS) issue. A reflected XSS attack can be used to non-permanently deface or modify displayed content on a website. Additionally, attackers can steal another user’s authentication information, such as data related to their current session, which may be used to impersonate the user and access information with the same privileges. If an administrator is impersonated, it could lead to a full compromise of the application’s security.

Full note on SAP: SAP Support Launchpad note 1520314

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More