Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized modification of displayed content in UR, SAP security note 1637338

SAP Note 1637338

SAP security note 1637338, "Unauthorized modification of displayed content in UR", is documented below with the symptom, SAP recommended solution and the affected software components.

Description

Symptom

Unified Rendering (UR) in SAP can be exploited to allow attackers to modify displayed application content without authorization. This vulnerability may enable the theft of authentication information from legitimate users through reflected cross-site scripting (XSS) attacks. Such attacks can lead to session hijacking, allowing attackers to impersonate users and gain unauthorized access to information and functionalities.

Solution

To address this security vulnerability, implement the following corrections:

  • Apply the corrections provided in SAP Note 1637338.
  • Additionally, ensure to review and apply framework-specific notes: HTMLB SAP Note 1653473, WD JAVA SAP Note 1653474.

References

Affected components

  • Basis Components > Web Dynpro > Unified Rendering (BC-WD-UR)

Full note on SAP: SAP Support Launchpad note 1637338

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More