Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized modification of stored content in SCM IBP, SAP security note 2279383

SAP Note 2279383
SAP Security Note
Medium priority

SAP security note 2279383, “Unauthorized modification of stored content in SCM IBP”, is a program error note released on 02.03.2016. Below are the symptom, SAP recommended solution and the affected software components.

ComponentSupply Chain Management > Integrated Business Planning > Analytics (SCM-IBP-ANA)
CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
Version3
StatusReleased for Customer
Released on02.03.2016

Description

Symptom

This security note addresses a Stored Cross-Site Scripting (XSS) vulnerability in SCM IBP. An attacker could exploit this vulnerability to modify application content without authorization and potentially steal authentication information from legitimate users.

Fiori Applications improperly encode URL content, leading to a stored XSS vulnerability. This allows attackers to permanently modify displayed content on a website, embed malicious content that is rendered automatically, and steal authentication information such as session data. If an attacker impersonates an administrator, the entire security of the application may be compromised.

Solution

Apply SAP Security Note 2279383 to resolve the vulnerability.

Reason and prerequisites

Ensure that SAP Note 2226757 titled “User name missing in analytics overview” is applied for component SCM-IBP-ANA.

Affected components

  • SCMIBPUI (Version 100)

Full note on SAP: SAP Support Launchpad note 2279383

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More