SAP security note 2131064, "Unauthorized modification of displayed content in Performance Management Application". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
The Performance Management Application can be exploited by an attacker to modify displayed application content without authorization. Additionally, an attacker might obtain authentication information from other legitimate users.
Solution
This issue has been resolved. The fix is available through the relevant Support Packages and Patches. Please refer to the Support Packages and Patches section for more details.
Reason and prerequisites
The aa-new-analytic-topbar page within the Performance Management Application does not sufficiently encode OUTPUT parameters, resulting in a reflected Cross-Site Scripting (XSS) vulnerability. This can be exploited to non-permanently deface or modify displayed content on the website.
An attacker exploiting this vulnerability can steal another user’s authentication information, such as session data. With this information, the attacker may impersonate the user and access all resources available to the target user. If an administrator is impersonated, the application’s security could be fully compromised.
CVSS
Score 4.3 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N
Affected components
- ENTERPRISE 4.0
- ENTERPRISE 410
- ENTERPRISE 420
Full note on SAP: SAP Support Launchpad note 2131064
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
