Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized modification of displayed content in BIW, SAP security note 1857350

SAP Note 1857350
SAP Security Note

SAP security note 1857350, “Unauthorized modification of displayed content in BIW”, was released on July 9, 2013. Below are the symptom, SAP recommended solution and the affected software components.

TypeSAP Security Note
Released onJuly 9, 2013

Description

Symptom

BI Workspaces can be abused by an attacker, allowing them to modify displayed application content without authorization, and potentially obtain authentication information from other legitimate users.

Solution

Apply one of the following patches, according to the installed version:

  • SAP BusinessObjects XI4.0 Patch4.15
  • SAP BusinessObjects XI4.0 Patch5.9
  • SAP BusinessObjects XI4.0 Patch6.1
  • SAP BusinessObjects XI4.0 SP7 onwards

Reason and prerequisites

Pages within BI Workspaces do not sufficiently encode output parameters, resulting in a reflected cross-site scripting issue. An attacker can steal user authentication information, impersonate users, and potentially compromise the security of the application.

CVSS

Score 4.3 Vector: AV:N/AC:M/AU:N/C:N/I:P/A:N

Affected components

  • Business intelligence solutions > Business intelligence platform > BI Workspaces (Dashboard Builder)

Full note on SAP: SAP Support Launchpad note 1857350

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More