Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Security Note Cross Site scripting in System Info NWA, SAP security note 1169367

SAP Note 1169367
SAP Security Note
Medium priority

SAP security note 1169367, "Cross Site Scripting in System Info NWA", is a program error note released on 08.10.2009. Below are the symptom and the SAP recommended solution.

ComponentBasis Components > NetWeaver Application Server Java > Local Admin Tools > Administration
CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
Version3
StatusReleased for Customer
Released on08.10.2009
LanguageEnglish

Description

Symptom

System Info in NWA is not escaping some special characters.

Solution

Special characters are escaped and URL manipulation with the intention for cross-site scripting is not possible through System Info in NWA.

Solution is available in:

  • 640 SP23
  • 700 SP16
  • 701 SP0
  • 710 SP7
  • 711 SP0

Reason and prerequisites

Special characters are not escaped.

Full note on SAP: SAP Support Launchpad note 1169367

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More