SAP security note 1595111, "Unauthorized modification of displayed content in Portal", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
This SAP Security Note addresses a reflected cross-site scripting (XSS) vulnerability in com.sap.portal.wsrp. A malicious user could exploit this vulnerability to modify displayed application content without authorization and potentially steal authentication information from other legitimate users. This could lead to unauthorized access and impersonation of users, including administrators, compromising the security of the application.
Solution
The vulnerable applications have been removed from the portal. To ensure system security, apply the relevant patches from the "SP Patch Level" section.
Affected components
- EP-PSERV: Versions 7.00 to 7.02
- EP-APPS-EXT: Versions 7.10 to 7.31
Full note on SAP: SAP Support Launchpad note 1595111
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



