Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized modification of displayed content in BOE, SAP security note 1749111

SAP Note 1749111
SAP Security Note
Medium priority

SAP security note 1749111, “Unauthorized modification of displayed content in BOE”, is a note released on April 9, 2013. Below are the symptom and SAP recommended solution.

ComponentBusiness intelligence solutions > Business intelligence platform > BI Servers, security, Crystal Reports in Launchpad
PriorityCorrection with medium priority
TypeSAP Security Note
Version4
Released onApril 9, 2013
LanguageEnglish

Description

Symptom

BusinessObjects BI Launch Pad can be abused by an attacker, allowing them to modify displayed application content without authorization, and to potentially obtain authentication information from other legitimate users.

Solution

Apply one of the following based on your installed version:

  • SAP BusinessObjects BI platform 4 (XI4.0) SP2 FixPack20 (2.20)
  • SAP BusinessObjects BI platform 4 (XI4.0) FeaturePack3 FixPack 9
  • SAP BusinessObjects BI platform 4 (XI4.0) SP4 FixPack 3
  • SAP BusinessObjects BI platform 4 (XI4.0) SP5 and higher versions

Reason and prerequisites

Pages within BusinessObjects BI Launch Pad do not sufficiently encode input parameters, resulting in a reflected cross-site scripting (XSS) issue. This vulnerability can be exploited to deface or modify displayed content and steal user authentication information, potentially allowing attackers to impersonate users or administrators.

CVSS

Score 3.5 Vector: AV:N/AC:M/AU:S/C:P/I:N/A:N

Full note on SAP: SAP Support Launchpad note 1749111

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More