SAP Security Note
Medium priority
SAP security note 1493268, "Unauthorized modification of displayed content in BW", is a program error note released on 03.02.2011. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
This security note addresses a vulnerability where a BW interface with portals can be exploited by a malicious user to modify displayed application content without authorization. This could potentially allow the attacker to obtain authentication information from other legitimate users.
Solution
- Deactivate SICF Internet Service: deactivate the internet service
/default_host/sap/bw/drif the drag&relate feature is not used. This applies to most BW customers. - Implement Support Package: apply the corresponding support package provided by SAP.
- Urgent Cases: if you need to keep the drag&relate service active, implement the provided correction instructions immediately.
Reason and prerequisites
The API interface within the BW portal integration does not sufficiently encode output parameters, resulting in a reflected cross-site scripting issue. An attacker can use this vulnerability to deface or modify web content temporarily or steal another user’s authentication information, potentially compromising the application’s security.
Affected components
- SAP_BW (30B, 310, 350, 700 to 702, 730)
- SAP_BW_VIRTUAL_COMP (30B, 701)
Full note on SAP: SAP Support Launchpad note 1493268
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
