Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized modification of displayed content in ROS, SAP security note 1478860

SAP Note 1478860
SAP Security Note

SAP security note 1478860, "Unauthorized Modification of Displayed Content in ROS", released on August 10, 2010. Below are the symptom, SAP recommended solution and the affected software components.

ComponentSupplier Relationship Management > Supplier Registration (SRM-ROS)
TypeSAP Security Note
Version6
Released onAugust 10, 2010

Description

Symptom

A vulnerability exists in the SAP SRM application that allows a malicious user to modify displayed application content without authorization. This can potentially lead to the theft of authentication information from other legitimate users. The issue stems from insufficient encoding of input and output parameters in the ROS_PRESCREEN BSP-Page SEARCH.HTM, resulting in a reflected Cross-Site Scripting (XSS) vulnerability. An attacker exploiting this can perform unauthorized actions, impersonate users, and compromise application security.

Solution

To mitigate this vulnerability, it is recommended to implement the provided correction instructions or import the corresponding support package for your SRM_SERVER version.

Reason and prerequisites

Ensure that SAP Note 1401379, Characters after Double Quotes are removed in Supplier name, is applied before implementing this security note.

References

Affected components

  • SAP SRM 5.0
  • SAP SRM 5.5
  • SAP SRM 6.0
  • SAP SRM 7.0
  • SAP SRM 7.01

Full note on SAP: SAP Support Launchpad note 1478860

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More