Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

XSS in ShowMemLog & ControlLog, SAP security note 1443659

SAP Note 1443659

SAP security note 1443659, "XSS in ShowMemLog & ControlLog". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

Several cross-site scripting (XSS) vulnerabilities have been discovered in the administrative web interfaces of ESR.

Solution

Apply the provided patch to fix the security issues, which prevent script injection attacks via URL parameters in XI administrative tools.

Affected components

  • SAP NetWeaver 2004
  • SAP NetWeaver 2004S
  • SAP NetWeaver PI 7.1
  • SAP EHP1 for SAP PI NetWeaver 7.1

Full note on SAP: SAP Support Launchpad note 1443659

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More