SAP security note 1414089, "Potential disclosure of authentication information in XI". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
SAP Note 1414089 addresses a Cross-Site Scripting (XSS) vulnerability in the remote ABAP API used by NetWeaver Process Integration Runtime Workbench (RWB). This vulnerability allows remote attackers to inject arbitrary scripts or HTML via a submission, potentially leading to unauthorized disclosure of authentication information.
Solution
To mitigate this vulnerability, apply the relevant support package that includes the provided patch. The patch ensures that HTTP input parameters are properly HTML-escaped before being returned to the client, thus preventing reflective XSS attacks.
References
- SAP EHP1 FOR SAP NETWEAVER PI 7.1 SP05
- Automatic checks for security notes using RSECNOTE (outdated)
Affected components
- SAP_BASIS 640
- SAP_BASIS 700
- SAP_BASIS 701
- SAP_BASIS 702
- SAP_BASIS 710
- SAP_BASIS 711
Full note on SAP: SAP Support Launchpad note 1414089
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



