SAP Security Note
High priority
SAP security note 2204160, "Unauthorized modification of displayed content in SAPUI5", is a program error note released on 08.12.2015. Below are the symptom, SAP recommended solution and CVSS assessment for this vulnerability.
Description
Symptom
SAPUI5 can be exploited by an attacker to modify displayed application content without authorization. This vulnerability may also allow attackers to obtain authentication information from legitimate users.
Solution
To mitigate this vulnerability, install the required SAP Notes as outlined below.
Reason and prerequisites
The Support Tool within SAPUI5 does not sufficiently encode input parameters, leading to a reflected cross-site scripting (XSS) vulnerability. An attacker can exploit this to deface or modify displayed content and steal authentication information, potentially compromising the security of the application.
CVSS
Score 4.3 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N
Full note on SAP: SAP Support Launchpad note 2204160
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
