SAP security note 2010153, “Unauthorized modification of displayed content in portal page toolbar”. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
The portal page toolbar iView can be abused by an attacker, allowing them to modify displayed application content without authorization, and to potentially obtain authentication information from other legitimate users.
Solution
Refer to Support Packages & Patches to view the versions including the fix.
CVSS
Score 4.3 Vector: AV:N/AC:M/AU:N/C:N/I:P/A:N
References
- 2009134 – Central Note for Portal Platform in NW702 SP17
- 2009087 – Central Note for NetWeaver 7.30 SP13 EP / EPC
- 2000190 – Central Note for Portal Platform in SAP NW7.0 EhP1 SP17
- 2000165 – Central Note for Portal Platform in SAP NW7.0 SP32
- 1989215 – Central Note for NetWeaver 7.40 SP08 EP / EPC
- 1983307 – Central Note for NetWeaver 7.31 SP13 EP / EPC
- 1923490 – Central Note for Portal Platform in SAP NW7.1 EhP1 SP14
- 1923086 – SAP NetWeaver CE Portal Platform NW7.10 SP19
Affected components
- Enterprise Portal > SAP Enterprise Portal (On Premise) > Navigation
Full note on SAP: SAP Support Launchpad note 2010153
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
