Medium priority
SAP security note 1987210, "Unauthorized modification of stored content in Payroll Data Source Framework", is a note released on 05.03.2014. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
The Payroll Data Source Framework can be abused by an attacker to modify application content, persist the changes without authorization, and potentially obtain authentication information from other legitimate users.
This vulnerability allows for stored cross-site scripting (XSS), enabling attackers to:
- Steal user authentication information.
- Impersonate users.
- Potentially compromise the security of the entire application if an administrator is targeted.
Solution
Apply the following correction instructions to resolve the issue.
Reason and prerequisites
The OData service PYD_FRW provided by the Payroll Data Source Framework results in a stored XSS issue. This service is only active if the Business Function HCM_LOC_CI_62 ("Payroll Data Source Framework") is enabled.
Affected components
- SAP_HRRXX from version 608 onwards
Full note on SAP: SAP Support Launchpad note 1987210
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
