Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized modification of stored content in Logon screen, SAP security note 1747396

SAP Note 1747396SAP Security NoteMedium priority

SAP security note 1747396, "Unauthorized modification of stored content in Logon screen", is released on 30.10.2012. Below are the symptom and SAP recommended solution.

ComponentSupplier Relationship Management > SRM > Technical Issues > ITS and Web files
PriorityCorrection with medium priority
TypeSAP Security Note
Version4
StatusReleased for Customer
Released on30.10.2012

Description

Symptom

Attackers can abuse the SRM logon page to inject malicious code that is stored and rendered when other users access the page.

Solution

This security note addresses the vulnerability by fixing the code injection issue. To resolve the problem, please import the relevant Support Package or implement the attached correction instructions.

Reason and prerequisites

Inadequate input validation on the SRM logon screen leads to stored XSS vulnerabilities, potentially compromising user sessions and allowing attackers to impersonate administrators.

CVSS

Score 0

References

Full note on SAP: SAP Support Launchpad note 1747396

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More