Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized modification of displayed content in BI-RA-WBI, SAP security note 1583982

SAP Note 1583982
SAP Security Note
High priority

SAP security note 1583982, "Unauthorized Modification of Displayed Content in BI-RA-WBI", is a program error note released on December 13, 2011. Below are the symptom and SAP recommended solution.

ComponentBI-RA-WBI (Business Intelligence Solutions > Reporting, Analysis, and Dashboards > Web Intelligence)
CategoryProgram Error
PriorityCorrection with High Priority
TypeSAP Security Note
Version2
StatusReleased for Customer
Released onDecember 13, 2011
LanguageEnglish

Description

Symptom

A vulnerability exists in BI-RA-WBI / SBOP XI 3.1 Web Intelligence that allows a malicious user to modify displayed application content without authorization. This flaw can potentially enable the attacker to obtain authentication information from other legitimate users.

Solution

To mitigate this issue, customers should install FixPack 2.8 or higher for SBOP XI 3.1.

Reason and prerequisites

The issue stems from insufficient encoding of input parameters in BI-RA-WBI / SBOP XI 3.1 Web Intelligence, leading to a reflected Cross-Site Scripting (XSS) vulnerability. Exploiting this vulnerability allows an attacker to deface or modify website content temporarily and potentially steal authentication information, enabling user impersonation and unauthorized access.

CVSS

Score 4.3 Vector: AV:N/AC:M/AU:N/C:N/I:P/A:N

Full note on SAP: SAP Support Launchpad note 1583982

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More