Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized modification of displayed content in Portal, SAP security note 1595111

SAP Note 1595111

SAP security note 1595111, "Unauthorized modification of displayed content in Portal", is a note. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

This SAP Security Note addresses a reflected cross-site scripting (XSS) vulnerability in com.sap.portal.wsrp. A malicious user could exploit this vulnerability to modify displayed application content without authorization and potentially steal authentication information from other legitimate users. This could lead to unauthorized access and impersonation of users, including administrators, compromising the security of the application.

Solution

The vulnerable applications have been removed from the portal. To ensure system security, apply the relevant patches from the "SP Patch Level" section.

Affected components

  • EP-PSERV: Versions 7.00 to 7.02
  • EP-APPS-EXT: Versions 7.10 to 7.31

Full note on SAP: SAP Support Launchpad note 1595111

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More