Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Cross-Site Scripting (XSS) vulnerability in SAPGUI for HTML, SAP security note 2471209

SAP Note 2471209
SAP Security Note
Medium priority

SAP security note 2471209, "Cross-Site Scripting (XSS) vulnerability in SAPGUI for HTML", is a note released on 12.10.2017. Below are the symptom, SAP recommended solution and the affected software components.

ComponentBasis Components > Frontend Services (SAP Note 1322184) > SAP Internet Transaction Server
PriorityCorrection with medium priority
TypeSAP Security Note
Version5
StatusReleased for Customer
Released on12.10.2017

Description

Symptom

UPDATE 12th October 2017: This note has been re-released with updated “Support Packages & Patches” information.

SAPGUI for HTML does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability.

Impacts of XSS Vulnerability:

  • Non-permanently deface or modify displayed content from a website
  • Steal authentication information of the user, such as data relating to their current session
  • Impersonate the user and access all information with the same rights as the target user

Solution

The vulnerability described above is resolved by a new Unified Rendering version, which provides proper output encoding in place.

  • Install the new Unified Rendering version by implementing the Support Packages and Patches referenced by this SAP Note.
  • Refer to SAP Note 2478692 for additional information on how to install the new Unified Rendering version.

CVSS

Score 6.1 / 10 Vector: AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

References

Affected components

  • SAP KERNEL 7.22, 7.22EXT, 7.49, 7.53
  • SAP KERNEL 7.45, 7.49, 7.53 (64-BIT and UNICODE variants)

Full note on SAP: SAP Support Launchpad note 2471209

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More