Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Code Injection vulnerability in SAP Web Dispatcher, SAP security note 2423429

SAP Note 2423429

SAP security note 2423429, “Code Injection vulnerability in SAP Web Dispatcher”. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

SAP Web Dispatcher permits an attacker to exceed the length of whitelists and blacklists stored in the x-forwarded-for HTTP header. This exploitation can conceal the attacker’s IP address, granting access to protected applications.

Solution

Apply the referenced SAP Web Dispatcher patch. The patch ensures that attackers cannot bypass the whitelists and blacklists by limiting the length of the x-forwarded-for HTTP header.

Reason and prerequisites

The vulnerability arises because SAP Web Dispatcher does not adequately validate the length of the x-forwarded-for HTTP header, allowing attackers to manipulate it and bypass access restrictions.

CVSS

Score 5.3 Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Affected components

  • Basis Components > Client/Server Technology > Web Dispatcher

Full note on SAP: SAP Support Launchpad note 2423429

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More