SAP Security Note
High priority
SAP security note 1668728, "Unauthorized modification of displayed content in SRM", is a program error note released on May 11, 2012. Below are the symptom and SAP recommended solution.
Description
Symptom
SRM can be abused by an attacker, allowing them to modify displayed application content without authorization, and to potentially obtain authentication information from other legitimate users.
Solution
Implement the attached correction or install the corresponding support package.
Reason and prerequisites
Within SRM attachment functionality, some parameters are not sufficiently encoded, resulting in a reflected cross-site scripting issue. A reflected cross-site scripting attack can be used to non-permanently deface or modify displayed content from a website.
Full note on SAP: SAP Support Launchpad note 1668728
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
