SAP security note 1992822, “Unauthorized modification of displayed content in BW-BEX-ET-WEB”, is a note. Below is the security information published by SAP for this note.
Description
Symptom
BW can be abused by a malicious user, allowing them to modify displayed application content without authorization and potentially obtain authentication information from other legitimate users.
Reason and prerequisites
Pages within BW-BEX-ET-WEB do not sufficiently encode output parameters, resulting in a reflected cross-site scripting vulnerability. This can be exploited to deface or modify displayed content temporarily and steal users' authentication information. A malicious user who gains access to this data may impersonate the user and access information with the same rights as the target user. If an administrator is impersonated, the security of the application may be fully compromised.
Solution
To mitigate this vulnerability, import the appropriate Support Package for your SAP BW version:
- SAP BW 7.00:
- The Support Package will be available once SAP Note 1930843 titled "SAPBWNews NW BW 7.0 ABAP SP34" is released.
- SAP BW 7.01 (SAP NW BW7.0 EHP 1):
- Available with SAP Note 2013377 titled "Preliminary Version SAPBWNews BW 7.01 ABAP SP17."
- SAP BW 7.02 (SAP NW BW7.0 EHP 2):
- Available with SAP Note 2017437 titled "Preliminary Version SAPBWNews BW 7.02 ABAP SP17."
- SAP BW 7.10:
- SAP BW 7.11:
- Available with SAP Note 1940531 titled "Preliminary Version SAPBINews NW7.11 BW ABAP SP14."
- SAP BW 7.20:
- SAP BW 7.30:
- Available with SAP Note 2021667 titled "SAPBWNews BW 7.30 ABAP SP13."
- SAP BW 7.31 (SAP NW BW 7.3 EHP 1):
- Available with SAP Note 1989585 titled "Preliminary Version SAPBWNews NW BW 7.31/7.03 ABAP SP13."
- SAP BW 7.40:
- Available with SAP Note 2000326 titled "Preliminary Version SAPBWNews NW BW 7.4 ABAP SP08."
You can also use the correction instructions to implement the fix prior to the availability of the Support Packages. Ensure that SAP Note 1623413 is implemented.
Before using the correction instructions, make sure to check SAP Note 1668882 for transaction SNOTE. This SAP Note might already be available before the Support Package is released. However, the short text may still indicate "preliminary version."
Full note on SAP: SAP Support Launchpad note 1992822
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
