SAP security note 1440336, "Unauthorized modification of displayed content- JPR". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Java Proxy Runtime (JPR) Transport servlet has a vulnerability to reflected Cross-Site Scripting (XSS) attacks.
An attacker may specify unknown values of parameters with malicious script commands, causing these scripts to execute in the user’s browser.
Solution
Apply the patch as per the Service Pack (SP) level. You can download the patch from the Download for SNOTE link or access the PDF version here.
Reason and prerequisites
The Java Proxy Runtime (JPR) Transport servlet does not sufficiently encode input parameters, making it vulnerable to reflected cross-site scripting attacks.
An attacker can present a victim with a malicious link. When the victim clicks the link, malicious script commands execute in the user’s browser. This can compromise the user’s security context, including browser cookies and cache objects. It can also cause the victim’s browser to automatically navigate to URLs on the vulnerable site, allowing the attacker to intrude into the security context of the victim.
Reflected XSS can be used to steal another user’s authentication information, such as session data. An attacker with access to this data could impersonate the user and access all information with the same permissions. If an administrator is impersonated, the application’s security could be fully compromised.
References
- 1616259 – Briefing at Black Hat conference on August 4th, 2011
- 1616164 – Procedure to deactivate SOAP Adapter and JPR applications
- 1476226 – NW04s XI Support Package Stack 22
- 1466811 – XI 30 Support Package Stack (SPS) 26
- 1459565 – SAP EHP1 FOR SAP NETWEAVER PI 7.1 SP05
Affected components
- Basis Components > NetWeaver Process Integration (PI) > Connectivity > Java Proxy Runtime
Full note on SAP: SAP Support Launchpad note 1440336
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



