SAP security note 1568003, "Unauthorized modification of displayed content in SystemInfo", is a note. Below are the symptom and SAP recommended solution.
Description
Symptom
The sap.com/tc~monitoring~systeminfo application (deprecated in SAP J2EE Engine 7.10 and above) contains JSP pages vulnerable to Cross-Site Scripting (XSS). An attacker can exploit this vulnerability to modify displayed application content without authorization and potentially obtain authentication information from other legitimate users.
Impact:
- Unauthorized Content Modification: Attackers can alter the content displayed within the application.
- Credential Theft: Potentially obtain authentication information from other users.
- User Impersonation: Use stolen credentials to impersonate users, including administrators, compromising the entire application’s security.
Solution
Upgrade your SAP J2EE Engine to a fixed version to mitigate this vulnerability.
CVSS
Score 4.3 Vector: AV:N/AC:M/AU:N/C:N/I:P/A:N
Full note on SAP: SAP Support Launchpad note 1568003
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
