SAP security note 2423429, “Code Injection vulnerability in SAP Web Dispatcher”. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
SAP Web Dispatcher permits an attacker to exceed the length of whitelists and blacklists stored in the x-forwarded-for HTTP header. This exploitation can conceal the attacker’s IP address, granting access to protected applications.
Solution
Apply the referenced SAP Web Dispatcher patch. The patch ensures that attackers cannot bypass the whitelists and blacklists by limiting the length of the x-forwarded-for HTTP header.
Reason and prerequisites
The vulnerability arises because SAP Web Dispatcher does not adequately validate the length of the x-forwarded-for HTTP header, allowing attackers to manipulate it and bypass access restrictions.
CVSS
Score 5.3 Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Affected components
- Basis Components > Client/Server Technology > Web Dispatcher
Full note on SAP: SAP Support Launchpad note 2423429
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



