SAP security note 1483888, "Unauthorized modification of displayed content in MMR". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Malicious users can exploit the MMR to alter displayed application content without proper authorization. This can lead to unauthorized access to sensitive authentication information from legitimate users.
Solution
The issue has been resolved in the following software versions:
- SAP NetWeaver 6.40 (formerly known as 2004) and BI META MODEL REPOSITORY 3.50 – SP 20, Software Component BI_MMR.SCA
- SAP NetWeaver 7.0 (formerly known as 2004s) – SP 11, Software Component BI_MMR.SCA
- SAP NetWeaver CE 7.10 – SP1, Software Component MMR_SERVER.SCA
For more details and updates, please refer to the SP Stack Schedule.
Reason and prerequisites
The vulnerability arises because pages within the MMR do not adequately encode input parameters, resulting in a reflected cross-site scripting (XSS) issue. An attacker can leverage this vulnerability to non-permanently deface or modify website content. Additionally, XSS can be used to steal authentication data, enabling attackers to impersonate users and potentially compromising the entire application’s security, especially if administrative accounts are targeted.
CVSS
Score 0
References
This note refers to
Referenced by
Affected components
- MMR_SERVER: Versions 7.10
- BI_MMR: Versions 3.50 and 7.00+
Full note on SAP: SAP Support Launchpad note 1483888
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
