SAP Security Note
Medium priority
SAP security note 1916861, “Unauthorized modification of displayed content in CA-WUI-UI”, is a note released on January 14, 2014. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
The CA-WUI-UI-TAG component does not sufficiently encode URL parameters, enabling attackers to perform reflected XSS attacks. This vulnerability can be exploited to modify displayed content or steal authentication information.
Solution
To mitigate this vulnerability, install the provided correction instructions or the corresponding Support Package. The available support packages can be found here.
CVSS
Score 4.3 Vector: AV:N/AC:M/AU:N/C:N/I:P/A:N
Affected components
- WEBCUIF versions 700, 701, 730, 731, 746, 747
Full note on SAP: SAP Support Launchpad note 1916861
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
