High priority
SAP security note 1612819, “Unauthorized modification of stored content in CA-GTF-TS-WSI”, was released on July 4, 2012. Below are the symptom and SAP recommended solution.
Description
Symptom
CA-GTF-TS-WSI can be exploited by malicious actors to:
- Modify application content without authorization.
- Persist modified content, leading to permanent changes.
- Steal authentication information from other users, potentially allowing impersonation and unauthorized data access.
Solution
To mitigate this vulnerability, implement the correction instructions provided in SAP Security Note 1612819. Detailed correction instructions can be downloaded here.
Reason and prerequisites
The vulnerability arises from inadequate input validation within the CA-GTF-TS-WSI component, which permits the storage and rendering of malicious scripts. This can lead to:
- Permanent modification of displayed web content.
- Automatic rendering of embedded malicious content without targeting individual victims.
- Theft of user authentication information, enabling impersonation and access to sensitive data.
Full note on SAP: SAP Support Launchpad note 1612819
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
