Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized modification of displayed content in SystemInfo, SAP security note 1568003

SAP Note 1568003

SAP security note 1568003, "Unauthorized modification of displayed content in SystemInfo", is a note. Below are the symptom and SAP recommended solution.

Description

Symptom

The sap.com/tc~monitoring~systeminfo application (deprecated in SAP J2EE Engine 7.10 and above) contains JSP pages vulnerable to Cross-Site Scripting (XSS). An attacker can exploit this vulnerability to modify displayed application content without authorization and potentially obtain authentication information from other legitimate users.

Impact:

  • Unauthorized Content Modification: Attackers can alter the content displayed within the application.
  • Credential Theft: Potentially obtain authentication information from other users.
  • User Impersonation: Use stolen credentials to impersonate users, including administrators, compromising the entire application’s security.

Solution

Upgrade your SAP J2EE Engine to a fixed version to mitigate this vulnerability.

CVSS

Score 4.3 Vector: AV:N/AC:M/AU:N/C:N/I:P/A:N

Full note on SAP: SAP Support Launchpad note 1568003

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More