Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Security note Web Administrator pages, SAP security note 1226252

SAP Note 1226252
Medium priority

SAP security note 1226252, “Security Note: Web Administrator Pages Vulnerability”, is a program error note released on 08.10.2009. Below are the symptom, SAP recommended solution and the affected software components.

CategoryProgram error
PriorityCorrection with medium priority
StatusReleased for Customer
Released on08.10.2009

Description

Symptom

SAP Security Note 1226252 addresses a critical vulnerability affecting the Web Administrator pages in SAP Web Dispatcher and ICM across kernel versions 6.40, 7.00, and 7.10. This security issue allows for potential cross-site scripting (XSS) attacks, which could compromise the integrity and security of your SAP systems.

The vulnerability affects ICM and SAP Web Dispatcher in the following kernel versions: 6.40, 7.00, and 7.10. Without applying the recommended patches, an attacker may exploit this vulnerability to perform cross-site scripting attacks on the SAP Web Dispatcher or ICM.

Solution

To mitigate this vulnerability, apply the corresponding kernel patches:

  • 6.40: SP254 (Patch Level 000254)
  • 7.00: SP173 (Patch Level 000173)
  • 7.10: SP117 (Patch Level 000117)

Additionally, as a temporary workaround, you can deactivate the Web Admin pages by commenting out the following parameter: icm/HTTP/admin_<x>. This action prevents access to the vulnerable admin pages until the patches can be applied.

Affected components

  • SAP_BASIS – Versions: 6.40, 7.00, 7.10
  • Client/Server Technology > Internet Communication Manager (BC-CST-IC)

Full note on SAP: SAP Support Launchpad note 1226252

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More