SAP Security Note
High priority
SAP security note 1494462, "Unauthorized modification of displayed content in ESRI Map", is a program error note released on December 14, 2010. Below are the symptom and SAP recommended solution.
Description
Symptom
A malicious user could abuse the ESRI Map to modify displayed application content without authorization and potentially obtain authentication information from other legitimate users.
Solution
Apply SAP Note 1494462.
Reason and prerequisites
The JavaScript API call to archweb services within the ESRI Map does not sufficiently encode input and output parameters, resulting in a reflected cross-site scripting (XSS) vulnerability. This flaw allows attackers to:
- Deface or modify displayed content non-permanently.
- Steal another user’s authentication information, potentially leading to impersonation and full compromise of the application’s security.
Full note on SAP: SAP Support Launchpad note 1494462
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
