Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Unauthorized modification of displayed content- SOAP Adapter, SAP security note 1438191

SAP Note 1438191

SAP security note 1438191, "Unauthorized modification of displayed content- SOAP Adapter". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

SOAP Adapter Helper servlet has a vulnerability to reflected Cross-Site Scripting (XSS) attacks. An attacker may specify an unrecognized value of an input parameter with malicious script commands, causing these commands to execute in the user’s browser.

Solution

Please apply the corresponding patch listed below.

Reason and prerequisites

The SOAP Adapter Helper servlet does not sufficiently encode input parameters, making it vulnerable to reflected cross-site scripting attacks. An attacker can present a malicious link to a victim, and clicking it can execute malicious scripts in the user’s browser. This compromises the user’s security context, including browser cookies and cache objects. It can also cause the victim’s browser to navigate to URLs on the vulnerable site, allowing the attacker to intrude into the user’s security context.

Reflected cross-site scripting can be used to steal another user’s authentication information, such as session data. An attacker with access to this data could impersonate the user and access all information with the same rights. If an administrator is impersonated, the application’s security could be fully compromised.

References

Affected components

  • 7.10 – SP6 patch level 39 or less
  • 7.10 – SP7 patch level 42 or less
  • 7.10 – SP8 patch level 22 or less
  • 7.10 – SP9 patch level 6 or less
  • 7.11 – EHP1 SP2 patch level 18 or less
  • 7.11 – EHP1 SP3 patch level 16 or less
  • 7.11 – EHP1 SP4 patch level 5 or less

Full note on SAP: SAP Support Launchpad note 1438191

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More