SAP Security Note
High priority
SAP security note 2381071, "Cross-Site AJAX Requests Vulnerability in SAP BusinessObjects", is a program error note released on August 8, 2017. Below are the symptom and SAP recommended solution.
Description
Symptom
An outdated version of the Prototype JS library was being used within BusinessObjects, allowing attackers to make "cross-site AJAX requests" via unknown vectors.
Solution
This issue is fixed in the patches listed in the "Support Package Patches" section below. To apply the fix, download and install the relevant support packages for your system.
For more details on the maintenance schedule and strategy, refer to Knowledge Base Article 2144559.
CVSS
Score 7.3 Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
References
Full note on SAP: SAP Support Launchpad note 2381071
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
