SAP security note 2175991, "Unauthorized modification of displayed content in Theme Integrity Test", released on August 11, 2015. Below are the symptom and SAP recommended solution.
Description
Symptom
A vulnerability has been identified in the com.sap.portal.themes.integrity component, which can be exploited by an attacker to modify displayed application content without authorization. This flaw may also allow attackers to obtain authentication information from legitimate users.
An attacker can perform reflected cross-site scripting (XSS) attacks by exploiting insufficient encoding of input parameters in the Theme Integrity Test. This can lead to unauthorized modification of content displayed on the web application and potentially steal user authentication information, posing a significant security risk.
Solution
Apply the relevant Support Package Patches to address this vulnerability.
CVSS
Score 4.3 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N
Full note on SAP: SAP Support Launchpad note 2175991
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
