Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized modification of displayed content in ISA-AUC, SAP security note 1603081

SAP Note 1603081

SAP security note 1603081, "Unauthorized modification of displayed content in ISA-AUC". Below are the symptom and SAP recommended solution.

Description

Symptom

  • Unauthorized modification of displayed content.
  • Potential theft of authentication data via XSS attacks.

Solution

This note provides Java corrections for E-Commerce and Web Channel.

  • Software Component: SAP-SHRWEB
  • Changed File: shops.jsp
  • Apply the Support Package patch level attached to this note.

For more information on applying Java patches, refer to Note 877887. See Note 1546959 for information about the patch strategy.

Reason and prerequisites

Insufficient encoding of output parameters on the shop list page within CRM-ISA-AUC, leading to a reflected XSS vulnerability.

References

Full note on SAP: SAP Support Launchpad note 1603081

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More