SAP security note 1997266, “Unauthorized modification of stored content in Portal Masthead”, is a program error note released on 12.08.2014. Below is the security information published by SAP for this note.
Description
#### Symptom
The Welcome String in the Portal Masthead can be abused by an attacker, allowing them to modify application content, persist the modified content without authorization, and potentially obtain authentication information from other legitimate users.
Solution
Refer to the "Support Packages & Patches" section below to view the versions that include the fix.
Download Links:
- Download for SNOTE
- PDF Version
References
- 2009134 – Central Note for Portal Platform in NW702 SP17
- 2000190 – Central Note for Portal Platform in SAP NW7.0 EhP1 SP17
- 1989215 – Central Note for NetWeaver 7.40 SP08 EP / EPC
- 1983307 – Central Note for NetWeaver 7.31 SP13 EP / EPC
- 1935631 – Central Note for NetWeaver 7.30 SP12 EP / EPC
- 1923490 – Central Note for Portal Platform in SAP NW7.1 EhP1 SP14
Full note on SAP: SAP Support Launchpad note 1997266
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
