SAP Security Note
High priority
SAP security note 1451843, "Missing input validation in SLD UI pages", is a program error note released on 28.01.2013. Below are the symptom and SAP recommended solution.
Description
Symptom
When you use HTTP to call Web pages, parts of the parameters for dynamic construction of these pages may be transferred. In certain situations, this can be used for cross-site scripting attacks.
Solution
Apply the relevant patches.
Reason and prerequisites
There is a danger of cross-site scripting on certain profile user interface (UI) pages.
References
- Briefing at Black Hat conference on August 4th, 2011
- SAP Netweaver for PI 7.10 Support Package 11
- SAP EHP1 FOR SAP NETWEAVER PI 7.1 SP06
- SAP EHP1 FOR SAP NETWEAVER PI 7.1 SP05
Full note on SAP: SAP Support Launchpad note 1451843
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
