SAP security note 1442580, "Potential disclosure of authentication information". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
The application ‘Alert-Configuration’ within XI/PI Runtime Workbench (RWB) can be exploited by a malicious user to obtain authentication information from other legitimate users.
Solution
The fix is available with the assigned Support Packages for the respective releases and is included starting from SAP_BASIS 7.30.
Reason and prerequisites
Certain pages within the RWB Alert-Configuration do not adequately encode input parameters, leading to reflected cross-site scripting issues and cross-domain redirection vulnerabilities.
Reflected XSS can be utilized to steal another user’s authentication information, such as session data, or to non-permanently deface a website. An attacker with access to this data could impersonate the user and access all information with the same privileges as the target user. If an administrator is impersonated, it may result in a full compromise of the application’s security.
Affected releases and support package levels:
- SAP BASIS 6.40 until SP26
- SAP BASIS 7.00 until SP22
- SAP BASIS 7.01 until SP07
- SAP BASIS 7.02 until SP04
- SAP BASIS 7.03 until SP01
- SAP BASIS 7.10 until SP10
- SAP BASIS 7.11 until SP05
- SAP BASIS 7.20 until SP03
References
- 1459565 – SAP EHP1 FOR SAP NETWEAVER PI 7.1 SP05
- 888889 – Automatic checks for security notes using RSECNOTE (outdated)
Full note on SAP: SAP Support Launchpad note 1442580
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
