Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

ILION Research Labs reported SAP ITS XSS exploit on Bugtraq, SAP security note 986992

SAP Note 986992

SAP security note 986992, "ILION Research Labs reported SAP ITS XSS exploit on Bugtraq". Below are the symptom and SAP recommended solution.

Description

Symptom

On Bugtraq, ILION Research Labs reported a Cross-Site Scripting (XSS) vulnerability in SAP Internet Transaction Server (ITS). The report can be accessed on SecurityFocus.

This SAP note informs SAP customers about SAP's view of the reported vulnerability.

Solution

  • ITS 6.20: apply the most current SAP ITS 6.20 patch level from the Service Marketplace.
  • SAP NetWeaver 2004: apply SAP Kernel patch 151 or higher as described in SAP Note 986444.

Reason and prerequisites

ITS 6.10 is affected by the issue. This release is out of maintenance since 31.12.2004, and SAP no longer creates patches for ITS 6.10. SAP highly recommends all customers upgrade ITS 6.10 installations to the latest ITS 6.20 patch level.

ITS 6.20 installations are affected by the reported exploit if the patch level is 17 or lower. SAP released patch level 18 in May 2005; customers who apply patches regularly should not be affected. The current patch level for ITS 6.20 is 22.

SAP NetWeaver 2004 with integrated ITS is affected by the ~urlmime issue up to SAP Kernel patch 150.

References

Full note on SAP: SAP Support Launchpad note 986992

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More