SAP security note 1686821, “Unauthorized modification of displayed content in SLC-SUP”, is a note. Below are the symptom and SAP recommended solution.
Description
Symptom
The application component SLC-QUA can be exploited by a malicious user to modify displayed application content without authorization. This vulnerability may also allow the attacker to obtain authentication information from other legitimate users.
Solution
Prerequisite notes: ensure that SAP Note 1582870 and SAP Note 1582867 are implemented via SNOTE as prerequisites before proceeding with this implementation.
You can apply this note directly or import the necessary changes through the relevant support package.
Reason and prerequisites
BSP applications using an extension tag depend on proper encoding. Missing or improper encoding within an extension can lead to XSS vulnerabilities in the BSP applications utilizing the extension.
Specifically, the BSP tags of the extensions /SRMSMC/QL_EXT and /SRMSMC/FRONTEND/ may be vulnerable to misuse through client modifications due to the absence of encoding for all attribute values passed to these extensions.
References
Full note on SAP: SAP Support Launchpad note 1686821
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



