SAP security note 1683929, "Unauthorized Modification of Stored Content in PT-RC-UI-XS". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An attacker can:
- Modify application content persistently without authorization.
- Embed malicious content that is automatically rendered.
- Steal authentication information, allowing impersonation of legitimate users, including administrators.
Solution
- Import the relevant Support Package for your SAP release.
- Implement the provided correction instructions available here.
Reason and prerequisites
The BSP applications ESS_LEAVEREQUEST_ADMIN and ESS_LEAVEREQUEST_APPROVER have a stored XSS vulnerability. This allows attackers to permanently alter displayed content on a website and steal authentication data.
References
- SAP Note 1654009: Encoding for applications in SAP_HR and EA-HR
- SAP Note 1600530: Unauthorized use of application functions in PT-RC-UI-XS
Affected components
- SAP_HRRXX (versions 470, 500, 600, 604)
Full note on SAP: SAP Support Launchpad note 1683929
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




