Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

NWBC Security problem launching sapgui out of HTML shell, SAP security note 1523755

SAP Note 1523755
SAP Security Note
High priority

SAP security note 1523755, "NWBC Security Problem: Launching SAPGUI Out of HTML Shell", is a program error note released on December 14, 2010. Below are the symptom and SAP recommended solution.

ComponentBasis Components > Web Dynpro > Clients > Please use BC-FES*
CategoryProgram Error
PriorityCorrection with High Priority
TypeSAP Security Note
Version2
StatusReleased for Customer
Released onDecember 14, 2010

Description

Symptom

A malicious user can trigger functionality in the NetWeaver Business Client (NWBC) without proper authentication and authorization.

Solution

Implement SAP Note 1523755 to address this security vulnerability.

Reason and prerequisites

The NetWeaver Business Client executes certain functions by referencing specific URLs. An attacker can trick an authenticated user’s browser into making a request with a crafted URL and specific parameters, causing the function to execute with the user’s privileges. This can be achieved through Cross Site Scripting (XSS) attacks or by persuading the victim to click on a malicious link.

References

Full note on SAP: SAP Support Launchpad note 1523755

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More