SAP security note 2560741, “[CVE-2018-2371] Cross-Site Scripting (XSS) Vulnerability in SAML 2.0 Service Provider of AS Java”. Below are the symptom and SAP recommended solution.
Description
Symptom
The SAML 2.0 service provider of Application Server (AS) Java does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability.
Impacts of XSS Vulnerability:
- Non-permanently defacing or modifying displayed content from a website.
- Stealing user authentication information, such as data related to the current session.
- Impersonating the user and accessing all information with the same rights as the target user.
Solution
Apply the latest patches relevant to the version of AS Java according to the “SP Patch Level” section of this note. With the described fix, the user-controlled input is sufficiently encoded.
Reason and prerequisites
Insufficient validation of the user input in the SAML 2.0 service provider of AS Java.
CVSS
Score 6.1 Vector: AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
References
This note refers to
- CVE-2018-2371
Referenced by
- 2566930 – Collective Note: SAP NetWeaver 7.30 SP18 – NWDS Update Site standalone
- 2567013 – Collective Note: SAP NetWeaver 7.30 SP18 – Application Server Java
- 2637693 – Central note for SAP NetWeaver 7.31 SP23 Application Server Java
- 2627601 – Collective Note: SAP NetWeaver 7.5 SP12 – Application Server Java (AS Java)
Full note on SAP: SAP Support Launchpad note 2560741
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
