SAP security note 2195595, "Multiple Security Vulnerabilities in SAP NetWeaver BSP Logon", is a program error note released on 13.10.2015. Below are the symptom and SAP recommended solution.
Description
Symptom
Multiple security vulnerabilities have been discovered in BSP (Business Server Pages) applications:
- Cross Site Scripting (XSS): The application is vulnerable to XSS attacks.
- URL Redirection: An attacker can host external resources in an iframe using the URL path when the user is authenticated. (CVSS Score: 4.3)
Solution
Please update SAP Basis to an SP or release where the issue is fixed. Refer to the Support Package section below for details and available patches.
Reason and prerequisites
The security vulnerabilities are found in the class CL_BSP_LOGIN_HANDLER used in BSP applications. This class is not protected against XSS and iframe-related security vulnerabilities. The obsolete class CL_BSP_LOGIN_HANDLER is no longer maintained and developed and will not be included in new SAP systems in the future.
CVSS
Score 4.3 / 10 Vector: AV:N/AC:M/PR:N/UI:N/S:U/C:N/I:P/A:N
Full note on SAP: SAP Support Launchpad note 2195595
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




