Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Cross-Site Scripting (XSS) vulnerability in UnifiedRendering, SAP security note 2333845

SAP Note 2333845
SAP Security Note
Medium priority

SAP security note 2333845, "Cross-Site Scripting (XSS) vulnerability in UnifiedRendering", is a program error note released on 14.03.2017. Below are the symptom and SAP recommended solution.

ComponentBasis Components > Web Dynpro > Unified Rendering (BC-WD-UR)
CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
Version3
StatusReleased for Customer
Released on14.03.2017
LanguageEnglish

Description

Symptom

UnifiedRendering does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability.

Some well-known impacts of XSS vulnerability include:

  • Non-permanently defacing or modifying displayed content from a website
  • Stealing authentication information of the user, such as data relating to their current session
  • Impersonating the user and accessing all information with the same rights as the target user

Solution

The issue described above is fixed by a rendering-related Web Dynpro for Java patch. Please install the relevant patch or a newer one, as patches are always cumulative.

CVSS

Score 5.4 Vector: AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Full note on SAP: SAP Support Launchpad note 2333845

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More