Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Composite Application Framework and Business Warehouse Test Integration, SAP security note 2405943

SAP Note 2405943

SAP security note 2405943, "Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Composite Application Framework and Business Warehouse Test Integration". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

A Cross-Site Scripting (XSS) vulnerability has been identified in the SAP NetWeaver Composite Application Framework (CAF) and Business Warehouse (BW) Test Integration. The integration test servlet does not sufficiently encode user-controlled inputs, allowing attackers to execute malicious scripts in the context of a user’s browser.

Potential impacts:

  • Deface or modify displayed content on a website.
  • Steal user authentication information, including session data.
  • Impersonate users to access information with their privileges.

Solution

To mitigate this vulnerability, apply the relevant Support Package Patches as outlined below.

CVSS

Score 6.1 Vector: AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected components

  • Composite Application Framework (CAF) 7.11
  • Composite Application Framework (CAF) 7.20
  • Composite Application Framework (CAF) 7.30

Full note on SAP: SAP Support Launchpad note 2405943

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More