Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized modification of displayed content in ESREGBASIC, SAP security note 1911067

SAP Note 1911067

SAP security note 1911067, "Unauthorized modification of displayed content in ESREGBASIC". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

ESREG-BASIC can be abused by an attacker, allowing them to modify displayed application content without authorization, and to potentially obtain authentication information from other legitimate users.

Solution

A patch for this issue is provided in the components specified in the Patch section of this note. The patches are available at SAP Service Marketplace as described in Note 952402.

CVSS

Score 4.3 Vector: AV:N/AC:M/AU:N/C:N/I:P/A:N

References

Affected components

  • ESREG-BASIC versions 7.20, 7.30, 7.31, 7.40

Full note on SAP: SAP Support Launchpad note 1911067

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More