SAP Security Note
SAP security note 1478860, "Unauthorized Modification of Displayed Content in ROS", released on August 10, 2010. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A vulnerability exists in the SAP SRM application that allows a malicious user to modify displayed application content without authorization. This can potentially lead to the theft of authentication information from other legitimate users. The issue stems from insufficient encoding of input and output parameters in the ROS_PRESCREEN BSP-Page SEARCH.HTM, resulting in a reflected Cross-Site Scripting (XSS) vulnerability. An attacker exploiting this can perform unauthorized actions, impersonate users, and compromise application security.
Solution
To mitigate this vulnerability, it is recommended to implement the provided correction instructions or import the corresponding support package for your SRM_SERVER version.
Reason and prerequisites
Ensure that SAP Note 1401379, Characters after Double Quotes are removed in Supplier name, is applied before implementing this security note.
References
Affected components
- SAP SRM 5.0
- SAP SRM 5.5
- SAP SRM 6.0
- SAP SRM 7.0
- SAP SRM 7.01
Full note on SAP: SAP Support Launchpad note 1478860
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
