Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized modification of displayed content in NetWeaver logon application, SAP security note 2090013

SAP Note 2090013
High priority

SAP security note 2090013, "Unauthorized modification of displayed content in NetWeaver logon application", is a program error note released on 11.08.2015. Below are the symptom and SAP recommended solution.

ComponentBasis Components > NetWeaver Application Server Java > Security, User Management
CategoryProgram error
PriorityCorrection with high priority
StatusReleased for Customer
Released on11.08.2015

Description

Symptom

The NetWeaver logon application can be abused by an attacker, allowing them to modify displayed application content without authorization and potentially obtain authentication information from other legitimate users.

Solution

Apply the latest patches relevant to the release and support package level of your AS Java as described in the "SP Patch Level" section of the note.

Reason and prerequisites

The logon pages within the NetWeaver logon application do not sufficiently encode input parameters, resulting in a reflected cross-site scripting (XSS) vulnerability. This can be exploited to deface or modify displayed content and steal user authentication information, potentially allowing attackers to impersonate users with the same rights.

CVSS

Score 4.3 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Full note on SAP: SAP Support Launchpad note 2090013

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More