Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized modification of displayed content in ESRI Map, SAP security note 1494462

SAP Note 1494462
SAP Security Note
High priority

SAP security note 1494462, "Unauthorized modification of displayed content in ESRI Map", is a program error note released on December 14, 2010. Below are the symptom and SAP recommended solution.

ComponentCustomer Relationship Management > Resource Planning for Personnel Resources > Labour Resource Planning within Service (CRM-RPL-SRV)
CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
StatusReleased for Customer
Released onDecember 14, 2010
LanguageEnglish

Description

Symptom

A malicious user could abuse the ESRI Map to modify displayed application content without authorization and potentially obtain authentication information from other legitimate users.

Solution

Apply SAP Note 1494462.

Reason and prerequisites

The JavaScript API call to archweb services within the ESRI Map does not sufficiently encode input and output parameters, resulting in a reflected cross-site scripting (XSS) vulnerability. This flaw allows attackers to:

  • Deface or modify displayed content non-permanently.
  • Steal another user’s authentication information, potentially leading to impersonation and full compromise of the application’s security.

Full note on SAP: SAP Support Launchpad note 1494462

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More