Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Cross-Site Scripting (XSS) vulnerability in Web Dynpro ABAP, SAP security note 2488516

SAP Note 2488516

SAP security note 2488516, “Cross-Site Scripting (XSS) vulnerability in Web Dynpro ABAP”. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

Web Dynpro ABAP does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability. This can allow attackers to deface content, steal user session information, or impersonate users.

Solution

The vulnerability is resolved by updating the Unified Rendering part of Web Dynpro ABAP as described in SAP Note 2090746 (“Unified Rendering Update – Instructions and Related Notes”) or by importing the relevant Support Package (e.g., SAPKB73121 for SAP_BASIS release 731).

CVSS

Score 6.1 Vector: AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

References

Affected components

  • SAP_UI 740, 750, 751
  • SAP_BASIS 702, 730, 731

Full note on SAP: SAP Support Launchpad note 2488516

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More