Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized modification of displayed content in VE, SAP security note 1673645

SAP Note 1673645

SAP security note 1673645, "Unauthorized modification of displayed content in VE", is a note. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

The SRM Vendor Evaluation application can be exploited by an attacker to modify displayed content without authorization. This vulnerability may allow attackers to obtain authentication information from other legitimate users.

Solution

To mitigate this vulnerability, import the corresponding support package as detailed below.

Reason and prerequisites

The vendor evaluation page within SRM-EBP-VE does not sufficiently encode output parameters, resulting in a reflected cross-site scripting issue. This vulnerability can be exploited to:

  • Temporarily deface or modify displayed web content.
  • Steal user authentication information, potentially allowing attackers to impersonate users and access sensitive data with the same privileges.

Affected components

  • SRM_SERVER 500
  • SRM_SERVER 550
  • SRM_SERVER 600
  • SRM_SERVER 700
  • SRM_SERVER 701
  • SRM_SERVER 702

Full note on SAP: SAP Support Launchpad note 1673645

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More