SAP security note 2182154, "Unauthorized modification of stored content in XMLForms Preview", was released on 28.07.2016. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
XMLForms Preview can be exploited by an attacker to modify application content, persist unauthorized changes, and potentially obtain authentication information from other legitimate users. This vulnerability poses risks such as stolen authentication data and impersonation of users, including administrators, potentially compromising the full security of the application.
Solution
Apply the relevant support package patches that include the fix for this vulnerability.
CVSS
Score 3.5 / 10 Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N
References
Referenced by
- SAP Note 2305559 – Central Note for NetWeaver 7.31 SP18 Enterprise Portal
- SAP Note 2270703 – Collective Note: SAP NetWeaver 7.30 SP15 – Enterprise Portal
- SAP Note 2202221 – Central Note: SAP NetWeaver 7.5 SP01 – Enterprise Portal
- SAP Note 2215652 – Central Note for NetWeaver 7.31 SP17 Enterprise Portal
- SAP Note 2202188 – Central Note: SAP NetWeaver 7.5 SP00 – Enterprise Portal
Affected components
- KMC-CM 7.00 – 7.02
- KMC-CM 7.30
- KMC-CM 7.31
- KMC-CM 7.40
- KMC-CM 7.50
- EP-CM 6.0_640
Full note on SAP: SAP Support Launchpad note 2182154
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
