Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized modification of displayed content in SLC-SUP, SAP security note 1686821

SAP Note 1686821

SAP security note 1686821, “Unauthorized modification of displayed content in SLC-SUP”, is a note. Below are the symptom and SAP recommended solution.

Description

Symptom

The application component SLC-QUA can be exploited by a malicious user to modify displayed application content without authorization. This vulnerability may also allow the attacker to obtain authentication information from other legitimate users.

Solution

Prerequisite notes: ensure that SAP Note 1582870 and SAP Note 1582867 are implemented via SNOTE as prerequisites before proceeding with this implementation.

You can apply this note directly or import the necessary changes through the relevant support package.

Reason and prerequisites

BSP applications using an extension tag depend on proper encoding. Missing or improper encoding within an extension can lead to XSS vulnerabilities in the BSP applications utilizing the extension.

Specifically, the BSP tags of the extensions /SRMSMC/QL_EXT and /SRMSMC/FRONTEND/ may be vulnerable to misuse through client modifications due to the absence of encoding for all attribute values passed to these extensions.

References

Full note on SAP: SAP Support Launchpad note 1686821

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More