Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized modification of displayed content in the Portal, SAP security note 1589716

SAP Note 1589716
High priority

SAP security note 1589716, "Unauthorized modification of displayed content in the Portal", is a faq note released on November 8, 2011. Below are the symptom and SAP recommended solution.

ComponentEnterprise Portal > SAP Enterprise Portal (On Premise) > Portal Runtime
CategoryFAQ
PriorityCorrection with high priority
StatusReleased for Customer
Released onNovember 8, 2011

Description

Symptom

A reflected Cross Site Scripting (XSS) vulnerability exists within the Portal runtime. This allows attackers to:

  • Non-permanently deface or modify displayed content on the website.
  • Steal another user’s authentication information, potentially leading to impersonation and unauthorized access.
  • If an administrator is impersonated, it may result in a full compromise of the application’s security.

Solution

To address this security issue, apply the appropriate Support Package (SP) Patch Level. You can find the relevant patches under the “SP Patch Level” tab in this security note.

Reason and prerequisites

The issue arises because the Portal runtime does not sufficiently encode input parameters, resulting in a reflected XSS vulnerability. This allows attackers to:

  • Modify displayed content without authorization.
  • Steal authentication data from legitimate users.
  • Potentially impersonate users with the same access rights, including administrators, leading to significant security breaches.

CVSS

Score 4.3 Vector: AV:N/AC:M/AU:N/C:N/I:P/A:N

Full note on SAP: SAP Support Launchpad note 1589716

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More