Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized modification of displayed content in Performance Management Application, SAP security note 2131064

SAP Note 2131064

SAP security note 2131064, "Unauthorized modification of displayed content in Performance Management Application". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

The Performance Management Application can be exploited by an attacker to modify displayed application content without authorization. Additionally, an attacker might obtain authentication information from other legitimate users.

Solution

This issue has been resolved. The fix is available through the relevant Support Packages and Patches. Please refer to the Support Packages and Patches section for more details.

Reason and prerequisites

The aa-new-analytic-topbar page within the Performance Management Application does not sufficiently encode OUTPUT parameters, resulting in a reflected Cross-Site Scripting (XSS) vulnerability. This can be exploited to non-permanently deface or modify displayed content on the website.

An attacker exploiting this vulnerability can steal another user’s authentication information, such as session data. With this information, the attacker may impersonate the user and access all resources available to the target user. If an administrator is impersonated, the application’s security could be fully compromised.

CVSS

Score 4.3 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Affected components

  • ENTERPRISE 4.0
  • ENTERPRISE 410
  • ENTERPRISE 420

Full note on SAP: SAP Support Launchpad note 2131064

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More