SAP Security Note
High priority
SAP security note 1649117, "Unauthorized modification of displayed content in WebDynpro", is a note released on May 8, 2012. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Web Dynpro ABAP can be exploited by an attacker to modify displayed application content without authorization. This vulnerability may allow the attacker to obtain authentication information from other legitimate users.
Solution
Apply the appropriate service pack or correction instruction as detailed in this security note.
Reason and prerequisites
Applications and components within Web Dynpro ABAP do not sufficiently encode output parameters, resulting in a reflected cross-site scripting issue. An attacker can use this vulnerability to:
- Non-permanently deface or modify displayed content on a website.
- Steal a user’s authentication information, such as session data.
- Impersonate users, including administrators, potentially compromising the entire application’s security.
CVSS
Score 0
Affected components
- Basis Components > Web Dynpro > Web Dynpro ABAP (BC-WD-ABA)
Full note on SAP: SAP Support Launchpad note 1649117
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
