SAP Security Note
Medium priority
SAP security note 2263719, "Cross-Site Scripting (XSS) vulnerability in BC-WD-JAV", released on 12.04.2016. Below are the symptom and SAP recommended solution.
Description
Symptom
BC-WD-JAV does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability. Impacts include:
- Non-permanently defacing or modifying displayed content from a web site
- Stealing authentication information of the user, such as data relating to their current session
- Impersonating the user and accessing all information with the same rights as the target user
Solution
The URL parameters were not sufficiently encoded, but this issue has now been fixed.
Reason and prerequisites
Insufficient encoding of URL parameters in WebDynpro for Java results in a stored cross-site scripting issue.
CVSS
Score 6.1 Vector: AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
References
Full note on SAP: SAP Support Launchpad note 2263719
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
