SAP Security Note
High priority
SAP security note 1583982, "Unauthorized Modification of Displayed Content in BI-RA-WBI", is a program error note released on December 13, 2011. Below are the symptom and SAP recommended solution.
Description
Symptom
A vulnerability exists in BI-RA-WBI / SBOP XI 3.1 Web Intelligence that allows a malicious user to modify displayed application content without authorization. This flaw can potentially enable the attacker to obtain authentication information from other legitimate users.
Solution
To mitigate this issue, customers should install FixPack 2.8 or higher for SBOP XI 3.1.
Reason and prerequisites
The issue stems from insufficient encoding of input parameters in BI-RA-WBI / SBOP XI 3.1 Web Intelligence, leading to a reflected Cross-Site Scripting (XSS) vulnerability. Exploiting this vulnerability allows an attacker to deface or modify website content temporarily and potentially steal authentication information, enabling user impersonation and unauthorized access.
CVSS
Score 4.3 Vector: AV:N/AC:M/AU:N/C:N/I:P/A:N
Full note on SAP: SAP Support Launchpad note 1583982
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
