SAP security note 2173184, "XSS Vulnerabilities in HTMLB." Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
HTMLB can be abused by an attacker, allowing them to modify displayed application content.
UI elements within HTMLB do not sufficiently encode input parameters, resulting in a reflected cross-site scripting (XSS) issue. This vulnerability can be exploited to non-permanently deface or modify displayed content on a website. Additionally, attackers may steal users’ authentication information, leading to potential impersonation and unauthorized access.
Solution
The issue is fixed by applying the HTMLB for Java patch. Follow these steps:
- Download HTMLB for Java Patches: all patches are available on the SAP Service Marketplace.
- Release Specific Details: depending on your NetWeaver version, deploy the appropriate Support Package Archive (SCA) using the Software Deployment Manager (SDM).
- Recommendations: for portal usage, apply the latest relevant EPBC2 or EPBASIS.SCA available on the Service Marketplace. For portal independent usage, apply the latest FRAMEWORK.SCA from the Service Marketplace.
CVSS
Score 4.3 / 10
References
- 2206761 – Collective Note: SAP NetWeaver 7.02 SP18 – Application Server Java
- 2202224 – Central Note: SAP NetWeaver 7.5 SP01 – EP Core (Application Platform)
Affected components
- Enterprise Portal > SAP Enterprise Portal Development Kit (PDK) > HTMLB Business for Java
Full note on SAP: SAP Support Launchpad note 2173184
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
