SAP security note 1545965, "Unauthorized modification of displayed content in RoleUpload". Below are the symptom and SAP recommended solution.
Description
Symptom
The Role Upload can be abused by a malicious user, allowing them to modify displayed application content without authorization and potentially obtain authentication information from other legitimate users.
Solution
Apply the latest patches for your respective SAP NetWeaver versions or upgrade to a newer Support Package (SP). Below are the recommended updates:
- SAP NetWeaver 04: Update from SP25 to SP27.
- SAP NetWeaver 7.0: Update from SP19 to SP23.
- SAP Enhancement Package 1 for NetWeaver 7.0: Update from SP4 to SP8.
- SAP Enhancement Package 2 for NetWeaver 7.0: Update from SP3 to SP6.
- SAP NetWeaver 7.1: Update from SP7 to SP011.
- SAP Enhancement Package 1 for NetWeaver 7.1: Update from SP3 to SP6.
- SAP NetWeaver 7.2: Update from SP1 to SP4.
- SAP NetWeaver 7.3: Update from SP1 to SP2.
Reason and prerequisites
The Role Upload does not sufficiently encode input parameters, resulting in a reflected cross-site scripting (XSS) vulnerability. An attacker can use this vulnerability to:
- Deface or modify displayed content temporarily.
- Steal authentication information such as session data, which can be used to impersonate users.
- Compromise application security entirely if an administrator's credentials are stolen.
The vulnerability exists in the following releases or any version below:
- SAP NetWeaver 04 SP27
- SAP NetWeaver 7.0 SP23
- SAP Enhancement Package 1 SP8 for SAP NetWeaver 7.0
- SAP Enhancement Package 2 SP6 for SAP NetWeaver 7.0
- SAP NetWeaver 7.1 SP011
- SAP Enhancement Package 1 SP6 for SAP NetWeaver 7.1
- SAP NetWeaver 7.2 SP4
- SAP NetWeaver 7.3 SP2
Full note on SAP: SAP Support Launchpad note 1545965
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
