SAP security note 2131081, "Unauthorized modification of displayed content in Performance Management Application", is a note released on 22.05.2015. Below are the symptom and SAP recommended solution.
Description
Symptom
Performance Management Application can be abused by an attacker, allowing them to modify displayed application content without authorization, and potentially obtain authentication information from other legitimate users.
Solution
This issue has been resolved. Please refer to the Support Packages and Patches section to apply the necessary updates.
Reason and prerequisites
The intermediateSaveInfoView page within the Performance Management Application does not sufficiently encode OUTPUT parameters, resulting in a reflected cross-site scripting (XSS) vulnerability. An attacker can exploit this to non-permanently deface or modify displayed content on the website or steal users’ authentication information.
CVSS
Score 4.3 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N
References
Full note on SAP: SAP Support Launchpad note 2131081
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
