Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Cross-Site Scripting (XSS) vulnerability in BC-WD-JAV, SAP security note 2263719

SAP Note 2263719
SAP Security Note
Medium priority

SAP security note 2263719, "Cross-Site Scripting (XSS) vulnerability in BC-WD-JAV", released on 12.04.2016. Below are the symptom and SAP recommended solution.

ComponentBasis Components > Web Dynpro > WebDynpro Java
PriorityCorrection with medium priority
TypeSAP Security Note
Version6
StatusReleased for Customer
Released on12.04.2016

Description

Symptom

BC-WD-JAV does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability. Impacts include:

  • Non-permanently defacing or modifying displayed content from a web site
  • Stealing authentication information of the user, such as data relating to their current session
  • Impersonating the user and accessing all information with the same rights as the target user

Solution

The URL parameters were not sufficiently encoded, but this issue has now been fixed.

Reason and prerequisites

Insufficient encoding of URL parameters in WebDynpro for Java results in a stored cross-site scripting issue.

CVSS

Score 6.1 Vector: AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

References

Full note on SAP: SAP Support Launchpad note 2263719

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More