SAP security note 1475481, "Unauthorized modification of stored content in signature BSP", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
The digital signature functionality can be exploited by a malicious user to modify application content without authorization. This allows the attacker to persist the modified content and potentially obtain authentication information from other legitimate users.
Solution
Apply the provided corrections or import the relevant support packages to mitigate this vulnerability.
Reason and prerequisites
This vulnerability arises from a program error that leads to a stored cross-site scripting (XSS) issue. Stored XSS enables attackers to permanently alter the displayed content of a website, embedding malicious scripts that execute automatically. Additionally, it can be used to steal authentication information, such as session data, allowing attackers to impersonate users and gain unauthorized access to information and functionalities.
References
Affected components
- SAP SRM 6.0
- SAP SRM 7.0
- SAP SRM 7.01
Full note on SAP: SAP Support Launchpad note 1475481
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



