Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Crosssite scripting (XSS) vulnerabilities in admin page (PI), SAP security note 1512776

SAP Note 1512776High priority

SAP security note 1512776, “Crosssite scripting (XSS) vulnerabilities in admin page (PI)”, is a note released on December 14, 2010. Below is the security information published by SAP for this note.

ComponentBasis Components > NetWeaver Process Integration (PI) > Integration Builder – Design
PriorityCorrection with high priority
StatusReleased for Customer
Released onDecember 14, 2010

Description

Several cross site scripting (XSS) vulnerabilities have been discovered in the administrative Web interfaces of SAP Process Integration (PI).

Reason and prerequisites

Problem Description:

1. XI administrative tools exhibit several possibilities for script injection attacks via URL parameters. 2. Vulnerable parameters in the scripts are prone to XSS attacks.

Solution

Why Should Customers Apply the Patch?

Applying this patch fixes the security issues related to script injection attacks via URL parameters in XI administrative tools. Addressing these vulnerabilities is crucial to prevent potential security threats that could compromise your systems.

Affected Versions:

  • SAP NetWeaver 2004
  • SAP NetWeaver 2004S
  • SAP NetWeaver PI 7.1
  • SAP EHP1 for SAP PI NetWeaver 7.1

Affected SCA's:

  • SAP_XITOOL for release NW04/NW04S
  • SAP_XIESR and SAP_XITOOL for release SAP NetWeaver PI 7.1 and SAP EHP1 for SAP PI NetWeaver 7.1

Fixed Versions:

All affected versions are fixed. Details of the fixes include:

  • NW04 SP23
  • NW04S SP18
  • SAP NetWeaver 7.0 EHP1 SP02
  • SAP NetWeaver PI 7.1 SP7
  • SAP EHP1 for SAP NetWeaver PI 7.1 SP1

Where and How to Get the Fixed Versions:

You can obtain the fixed versions from the SAP Service Marketplace:

1. Navigate to Downloads. 2. Select SAP Support Package. 3. Enter by Application Group. 4. Choose SAP NetWeaver. 5. Select the desired Release. 6. Choose the desired SCA.

Additional information

  • Released On: December 14, 2010
  • Priority: Correction with high priority
  • Status: Released for Customer
  • Component: Basis Components > NetWeaver Process Integration (PI) > Integration Builder – Design

References

Full note on SAP: SAP Support Launchpad note 1512776

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More