SAP security note 2393021, "Adobe SDK XSS vulnerability – Flex". Below are the symptom and SAP recommended solution.
Description
Symptom
The binaries of the wd.flex project used in developing Flex applications are vulnerable to Cross Site Scripting (XSS) attacks. This vulnerability can be detected by downloading the Adobe tool from Adobe Flex Security Issue APSB11-25.
Solution
Adobe has provided a patched SDK that resolves the XSS vulnerability. We have incorporated this SDK into our framework. To mitigate the vulnerability, deploy the latest WDRUNTIME.sca on your systems. This ensures that the binaries delivered via WDRUNTIME are invulnerable to Cross Site Scripting attacks.
Reason and prerequisites
This vulnerability was identified in the third-party Adobe SDK. Consumers using the older, unpatched SDK will have vulnerable Flex binaries both in libraries and applications. Adobe has released a patched SDK that addresses this vulnerability.
Full note on SAP: SAP Support Launchpad note 2393021
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
