SAP Security Note
Medium priority
SAP security note 2332977, "Cross site scripting (XSS) vulnerability in Web Dynpro ABAP", is a program error note released on 14.03.2017. Below are the symptom and SAP recommended solution.
Description
Symptom
Web Dynpro ABAP can be exploited by an attacker to modify displayed application content without authorization and potentially obtain authentication information from other legitimate users. Impacts include:
- Defacing or modifying displayed content from a website temporarily.
- Stealing user authentication information, such as session data.
- Impersonating users to access information with their privileges, potentially compromising application security if an administrator is targeted.
Solution
Apply the relevant correction instructions as specified in this note. Detailed manual activities are required to update the Unified Rendering component of Web Dynpro ABAP. Refer to the following SAP Notes for specific updates:
- SAP_BASIS 702: SAP Note 2097342, Unified Rendering for SAP_BASIS 702
- SAP_BASIS 730: SAP Note 2154726, Unified Rendering for SAP_BASIS 730
- SAP_BASIS 731: SAP Note 2156710, Unified Rendering for SAP_BASIS 731
- SAP_UI 740: SAP Note 2154957, Unified Rendering for SAP_UI 740
- SAP_UI 750: SAP Note 2207387, Unified Rendering for SAP_UI 750
Reason and prerequisites
Pages within Web Dynpro ABAP do not sufficiently encode output parameters, leading to a reflected cross-site scripting (XSS) vulnerability.
CVSS
Score 5.4 Vector: AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
References
Full note on SAP: SAP Support Launchpad note 2332977
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




