SAP security note 2374767, “Cross-Site Scripting (XSS) vulnerability in SAPUI5”. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
SAPUI5 does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability. This vulnerability can allow attackers to:
- Non-permanently deface or modify displayed content from a website.
- Steal authentication information of the user, such as data related to their current session.
- Impersonate the user and access all information with the same rights as the target user.
Solution
Please install the latest UI5 patches available for your system. The solution is available for all supported UI5 versions.
For SAP HANA Platform:
- SAP HANA PLATFORM EDITION 2.0 SPS 02: Not affected; initial shipment contains an updated SAP UI5 version.
- SAP HANA PLATFORM EDITION 2.0 SPS 01: SAP HANA DATABASE 2.0 >= Maintenance Revision 012.01 (Release Date >= 25.08.2017); SAP EXTENDED APP SERVICES 1 / XS RUNTIME 1 >= Build 1.0.63 / Patch 63 / Patch Collection 33 (Release Date >= 26.07.2017); XS SERVICES 1 >= 1.0.63 / SP05 Patch 3 (Release Date >= 26.07.2017); XS MONITORING 1 >= SP05 Patch 2 (Release Date >= 24.07.2017); XSAC FILEPROCESSOR 1.0 >= SP00 Patch 3 (Release Date >= 13.07.2017).
- SAP HANA PLATFORM EDITION 1.0 SP 12: SAP HANA DATABASE 1.00 >= Maintenance Revision 122.12 (Release Date >= 24.08.2017); XS ADVANCED RUNTIME / SAP EXTENDED APP SERVICES 1 >= Build 1.0.63 / Patch 63 / Patch Collection 33 (Release Date >= 26.07.2017); XS ADVANCED SERVICES / XS SERVICES 1 >= 1.0.63 / SP05 Patch 3 (Release Date >= 26.07.2017); XS ADVANCED MONITORING / XS MONITORING 1 >= SP05 Patch 2 (Release Date >= 24.07.2017).
CVSS
Score 6.1 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Affected components
- HDB 1.00, 2.00
- UISAPUI5 100
- UISAPUI5_JAVA 7.30, 7.31, 7.40, 7.50
- SAP_UI 740, 750, 751
- UI_700 200
Full note on SAP: SAP Support Launchpad note 2374767
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



