SAP Security Note
Medium priority
SAP security note 2279383, “Unauthorized modification of stored content in SCM IBP”, is a program error note released on 02.03.2016. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
This security note addresses a Stored Cross-Site Scripting (XSS) vulnerability in SCM IBP. An attacker could exploit this vulnerability to modify application content without authorization and potentially steal authentication information from legitimate users.
Fiori Applications improperly encode URL content, leading to a stored XSS vulnerability. This allows attackers to permanently modify displayed content on a website, embed malicious content that is rendered automatically, and steal authentication information such as session data. If an attacker impersonates an administrator, the entire security of the application may be compromised.
Solution
Apply SAP Security Note 2279383 to resolve the vulnerability.
Reason and prerequisites
Ensure that SAP Note 2226757 titled “User name missing in analytics overview” is applied for component SCM-IBP-ANA.
Affected components
- SCMIBPUI (Version 100)
Full note on SAP: SAP Support Launchpad note 2279383
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
