Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized modification of stored content in signature BSP, SAP security note 1475481

SAP Note 1475481

SAP security note 1475481, "Unauthorized modification of stored content in signature BSP", is a note. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

The digital signature functionality can be exploited by a malicious user to modify application content without authorization. This allows the attacker to persist the modified content and potentially obtain authentication information from other legitimate users.

Solution

Apply the provided corrections or import the relevant support packages to mitigate this vulnerability.

Reason and prerequisites

This vulnerability arises from a program error that leads to a stored cross-site scripting (XSS) issue. Stored XSS enables attackers to permanently alter the displayed content of a website, embedding malicious scripts that execute automatically. Additionally, it can be used to steal authentication information, such as session data, allowing attackers to impersonate users and gain unauthorized access to information and functionalities.

References

Affected components

  • SAP SRM 6.0
  • SAP SRM 7.0
  • SAP SRM 7.01

Full note on SAP: SAP Support Launchpad note 1475481

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More