SAP security note 2081677, "Unauthorized modification of stored content in FIN-SEM-CPM". Below are the symptom and SAP recommended solution.
Description
Symptom
FIN-SEM-CPM can be abused by an attacker, allowing them to modify application content, persist the modified content without authorization, and potentially obtain authentication information from other legitimate users.
Solution
Apply the following correction instructions using transaction SNOTE.
Reason and prerequisites
Pages result in a stored cross-site scripting (XSS) issue. This vulnerability allows an attacker to permanently modify displayed content on a website, embed content that is automatically rendered without targeting victims individually, and steal another user’s authentication information, such as data related to their current session. If an administrator’s credentials are compromised, the security of the entire application may be fully compromised.
Full note on SAP: SAP Support Launchpad note 2081677
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




