Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized modification of displayed content in BOE, SAP security note 1762486

SAP Note 1762486
SAP Security Note

SAP security note 1762486, “Unauthorized modification of displayed content in BOE”, is a note released on April 9, 2013. Below are the symptom and SAP recommended solution.

ComponentBusiness Intelligence Solutions > Business Intelligence Platform > Webapp Deployment, Networking, Vulnerabilities, Webservices (BO-WEBAPP)
TypeSAP Security Note
StatusReleased for Customer
Released onApril 9, 2013

Description

Symptom

SAP Business Intelligence 4 can be abused by an attacker, allowing them to modify displayed application content without authorization, and potentially obtain authentication information from other legitimate users.

Solution

Customers are advised to install patch 2.16 or Service Pack 4 (SP4) for BI4 to address this vulnerability.

Reason and prerequisites

Pages within SAP BusinessObjects Enterprise do not sufficiently encode input parameters, resulting in a reflected cross-site scripting vulnerability. This can allow an attacker to non-permanently deface or modify displayed content on a website. Additionally, stolen authentication information can be used to impersonate users, potentially compromising the security of the entire application if an administrator is targeted.

An attacker exploiting this vulnerability can:

  • Modify displayed content without authorization.
  • Steal authentication information to impersonate legitimate users.
  • Potentially gain administrative access, compromising the entire application.

CVSS

Score 4.3 Vector: AV:N/AC:M/AU:N/C:N/I:P/A:N

Full note on SAP: SAP Support Launchpad note 1762486

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More