Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2020-6246 Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS ABAP ( Business Server Pages Test Application SBSPEXT_TABLE), SAP security note 2878935

SAP Note 2878935

SAP security note 2878935, “[CVE-2020-6246] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS ABAP (Business Server Pages Test Application SBSPEXT_TABLE)”, is a note released on June 9, 2020. Below are the symptom and SAP recommended solution.

Released onJune 9, 2020

Description

Symptom

A Cross-Site Scripting (XSS) vulnerability has been identified in the SAP NetWeaver AS ABAP – Business Server Pages Test Application SBSPEXT_TABLE. The application fails to sufficiently encode user-controlled inputs, which allows attackers to execute arbitrary scripts in the context of a user’s browser session.

Solution

SAP has provided patches that properly encode URL parameters to prevent XSS attacks. Administrators should ensure the SICF node /sap/bc/bsp/sap/sbspext_table is secured or disabled if not in use.

CVSS

Score 6.1

References

  • CVE-2020-6246

Full note on SAP: SAP Support Launchpad note 2878935

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More