SAP security note 1512776, “Crosssite scripting (XSS) vulnerabilities in admin page (PI)”, is a note released on December 14, 2010. Below is the security information published by SAP for this note.
Description
Several cross site scripting (XSS) vulnerabilities have been discovered in the administrative Web interfaces of SAP Process Integration (PI).
Reason and prerequisites
Problem Description:
1. XI administrative tools exhibit several possibilities for script injection attacks via URL parameters. 2. Vulnerable parameters in the scripts are prone to XSS attacks.
Solution
Why Should Customers Apply the Patch?
Applying this patch fixes the security issues related to script injection attacks via URL parameters in XI administrative tools. Addressing these vulnerabilities is crucial to prevent potential security threats that could compromise your systems.
Affected Versions:
- SAP NetWeaver 2004
- SAP NetWeaver 2004S
- SAP NetWeaver PI 7.1
- SAP EHP1 for SAP PI NetWeaver 7.1
Affected SCA's:
- SAP_XITOOL for release NW04/NW04S
- SAP_XIESR and SAP_XITOOL for release SAP NetWeaver PI 7.1 and SAP EHP1 for SAP PI NetWeaver 7.1
Fixed Versions:
All affected versions are fixed. Details of the fixes include:
- NW04 SP23
- NW04S SP18
- SAP NetWeaver 7.0 EHP1 SP02
- SAP NetWeaver PI 7.1 SP7
- SAP EHP1 for SAP NetWeaver PI 7.1 SP1
Where and How to Get the Fixed Versions:
You can obtain the fixed versions from the SAP Service Marketplace:
1. Navigate to Downloads. 2. Select SAP Support Package. 3. Enter by Application Group. 4. Choose SAP NetWeaver. 5. Select the desired Release. 6. Choose the desired SCA.
Additional information
- Released On: December 14, 2010
- Priority: Correction with high priority
- Status: Released for Customer
- Component: Basis Components > NetWeaver Process Integration (PI) > Integration Builder – Design
References
- SAP Note 1616259
- SAP Note 1570042
- SAP Note 1570041
- SAP Note 1564466
- SAP Note 1531912
- SAP Note 1459565
Full note on SAP: SAP Support Launchpad note 1512776
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



