SAP security note 1911067, "Unauthorized modification of displayed content in ESREGBASIC". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
ESREG-BASIC can be abused by an attacker, allowing them to modify displayed application content without authorization, and to potentially obtain authentication information from other legitimate users.
Solution
A patch for this issue is provided in the components specified in the Patch section of this note. The patches are available at SAP Service Marketplace as described in Note 952402.
CVSS
Score 4.3 Vector: AV:N/AC:M/AU:N/C:N/I:P/A:N
References
This note refers to
Affected components
- ESREG-BASIC versions 7.20, 7.30, 7.31, 7.40
Full note on SAP: SAP Support Launchpad note 1911067
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
