SAP Security Note
HotNews
SAP security note 891232, “BSP Security Relevant Changes”, is released on 08.10.2009. Below are the symptom and SAP recommended solution.
Description
Symptom
This security note addresses Cross-Site Scripting (XSS) and HTTP Header related vulnerabilities within the BSP runtime. Multiple enhancements have been implemented to bolster protection against these security threats.
Solution
HTTP Header Errors:
XSS Mitigations:
Activation of (Test) BSP Applications in Production Systems:
- SAP Note 517484: Inactive services in the Internet Communication Framework
- SAP Note 887164: BSP Test Applications in Production Systems
Programming Aspects:
- SAP Note 887168: BSP Page Directive <%@page forceEncode="html"%>
- SAP Note 944279: BSP Page Directive <%@page forceEncodeOtr="html"%>
- SAP Note 822881: XSS Support for BSP-Extensions HTMLB, XHTMLB and PHTMLB
References
- 944279: BSP Page Directive <%@page forceEncodeOtr="html"%> and <OTR>
- 887323: HTML Encoding of Error Messages
- 887322: Whitelist checks of sap-exit URL
- 887168: BSP Page Directive <%@page forceEncode="html"%> & <%html=%>
- 887164: BSP Test Applications in Production Systems
- 853878: HTTP WhiteList Check (security)
- 822881: XSS Support for BSP-Extensions HTMLB, XHTMLB and PHTMLB
- 517484: Inactive services in the Internet Communication Framework
Full note on SAP: SAP Support Launchpad note 891232
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
