SAP Security Note
High priority
SAP security note 1670438, “Unauthorized modification of ITS in SRM-EBP-ADM-USR”, is a program error note released on May 8, 2012. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A vulnerability exists in SRM-EBP-ADM-USR that allows a malicious user to modify displayed application content without authorization. This can be exploited to obtain authentication information from other legitimate users.
Solution
Apply this SAP Security Note or import the changes via the relevant support package.
Reason and prerequisites
The ITS Services BBPAT03, BBPUM01, BBPUM02, and BBPVENDOR within SRM-EBP-ADM-USR do not sufficiently encode OUTPUT parameters, resulting in a cross-site scripting issue. This vulnerability can be used to steal another user’s authentication information, potentially allowing impersonation and access to sensitive data with the same rights as the target user. If an administrator is impersonated, the security of the application may be fully compromised.
Affected components
- SRM_SERVER 500
- SRM_SERVER 550
- SRM_SERVER 600
- SRM_SERVER 700
- SRM_SERVER 701
- SRM_SERVER 702
Full note on SAP: SAP Support Launchpad note 1670438
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
