Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2019-0388 Content spoofing vulnerability in UI5 HTTP Handler, SAP security note 2843016

SAP Note 2843016

SAP security note 2843016, "[CVE-2019-0388] Content Spoofing Vulnerability in UI5 HTTP Handler." Below are the SAP recommended solution and the affected software components.

Description

Solution

For On-Premise Customers: Follow the detailed correction instructions provided in the note to update the UI5 HTTP Handler. This involves creating data elements, structures, message classes, log objects, and uploading document classes using various SAP transactions such as SE09, SE11, SE91, SLG0, SE24, and SE61. Detailed step-by-step instructions are available within the note.

For Cloud Customers: No action is required as all SAP S/4HANA Cloud tenants have already been upgraded with these fixes. For more information, visit the Cloud Availability Center and select "SAP S/4HANA Cloud."

CVSS

Score 4.3 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

References

Referenced by

  • SAP Note 2933551: SAP Note 2843016 implementation: class /UI5/CL_APPLICATION does not exist

Affected components

  • SAP_UI: Versions 750 to 754
  • UI_700: Version 200

Full note on SAP: SAP Support Launchpad note 2843016

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More