Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Content spoofing in AS Java Web container, SAP security note 2314976

SAP Note 2314976SAP Security NoteMedium priority

SAP security note 2314976, "Content Spoofing in AS Java Web Container", is a program error note released on 03.10.2017. Below are the symptom, SAP recommended solution and the affected software components.

ComponentBasis Components > NetWeaver Application Server Java > Web Container, HTTP, JavaMail, Servlets
CategoryProgram Error
PriorityCorrection with Medium Priority
TypeSAP Security Note
StatusReleased for Customer
Released on03.10.2017

Description

Symptom

AS Java Web Container does not sufficiently encode user-controlled inputs, resulting in a content spoofing vulnerability when error pages are displayed.

Solution

Update AS Java to the latest version. See the SP Patch Level section of this SAP Note for details.

Reason and prerequisites

Content spoofing is an attack technique used to trick a user into believing that certain content appearing on a website is legitimate and not from an external source. This attack is typically used as, or in conjunction with, social engineering because it exploits a code-based vulnerability and a user’s trust.

CVSS

Score 0

Affected components

  • ENGINEAPI 7.10 to 7.11
  • ENGINEAPI 7.30
  • ENGINEAPI 7.31
  • ENGINEAPI 7.40

Full note on SAP: SAP Support Launchpad note 2314976

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More