Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized modification of stored content in FIN-SEM-CPM, SAP security note 2081677

SAP Note 2081677

SAP security note 2081677, "Unauthorized modification of stored content in FIN-SEM-CPM". Below are the symptom and SAP recommended solution.

Description

Symptom

FIN-SEM-CPM can be abused by an attacker, allowing them to modify application content, persist the modified content without authorization, and potentially obtain authentication information from other legitimate users.

Solution

Apply the following correction instructions using transaction SNOTE.

Reason and prerequisites

Pages result in a stored cross-site scripting (XSS) issue. This vulnerability allows an attacker to permanently modify displayed content on a website, embed content that is automatically rendered without targeting victims individually, and steal another user’s authentication information, such as data related to their current session. If an administrator’s credentials are compromised, the security of the entire application may be fully compromised.

Full note on SAP: SAP Support Launchpad note 2081677

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More