SAP Security Note
Medium priority
SAP security note 2537545, "[CVE-2017-16685] Cross-Site Scripting (XSS) vulnerability in SAP BW Universal Data Integration", is a program error note released on 12.12.2017. Below are the symptom and SAP recommended solution.
Description
Symptom
SAP Business Warehouse (BW) Universal Data Integration (UDI) does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability.
Some well-known impacts of XSS vulnerability are:
- Non-permanently deface or modify displayed content from a Web site
- Steal authentication information of the user, such as data relating to their current session
- Impersonate the user and access all information with the same rights as the target user
Solution
Input encoding and validation have been added to fix the vulnerability. Please implement the Support Package or Patch referenced by this SAP Note.
CVSS
Score 6.9 / 10 Vector: AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N
References
Referenced by
- 2567025: Collective Note: SAP NetWeaver 7.30 SP18 – EP Core – Application Portal
- 2566957: Collective Note: SAP NetWeaver 7.30 SP18 – AS Java Extensions
- 2637703: Central Note for NetWeaver 7.31 SP23 Enterprise Portal Core
- 2637702: Central note for SAP NetWeaver 7.31 SP23 Composition App. Framework
- 2637684: Central Note for CAF for NW 731 SP23
- 2597775: Central Note: SAP NetWeaver 7.5 SP11 EP Core (Application Platform)
- 2597884: Collective Note: SAP NetWeaver 7.5 SP11 – Composition Platform
- 2552663: Collective note : SAP NETWEAVER 7.31 SP22 – Process Orchestration (PI)
Full note on SAP: SAP Support Launchpad note 2537545
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
