Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized modification of displayed content in SAPUI5, SAP security note 2204160

SAP Note 2204160
SAP Security Note
High priority

SAP security note 2204160, "Unauthorized modification of displayed content in SAPUI5", is a program error note released on 08.12.2015. Below are the symptom, SAP recommended solution and CVSS assessment for this vulnerability.

ComponentCA-UI5-COR (Cross-Application Components > SAPUI5 > Core and Runtime)
CategoryProgram error
PriorityHigh priority
TypeSAP Security Note
Version2
StatusReleased for Customer
Released on08.12.2015
LanguageEnglish

Description

Symptom

SAPUI5 can be exploited by an attacker to modify displayed application content without authorization. This vulnerability may also allow attackers to obtain authentication information from legitimate users.

Solution

To mitigate this vulnerability, install the required SAP Notes as outlined below.

Reason and prerequisites

The Support Tool within SAPUI5 does not sufficiently encode input parameters, leading to a reflected cross-site scripting (XSS) vulnerability. An attacker can exploit this to deface or modify displayed content and steal authentication information, potentially compromising the security of the application.

CVSS

Score 4.3 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Full note on SAP: SAP Support Launchpad note 2204160

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More