Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Cross site scripting (XSS) vulnerability in Web Dynpro ABAP, SAP security note 2332977

SAP Note 2332977
SAP Security Note
Medium priority

SAP security note 2332977, "Cross site scripting (XSS) vulnerability in Web Dynpro ABAP", is a program error note released on 14.03.2017. Below are the symptom and SAP recommended solution.

ComponentBasis Components > Web Dynpro > Web Dynpro ABAP (BC-WD-ABA)
CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
Version4
StatusReleased for Customer
Released on14.03.2017
LanguageEnglish

Description

Symptom

Web Dynpro ABAP can be exploited by an attacker to modify displayed application content without authorization and potentially obtain authentication information from other legitimate users. Impacts include:

  • Defacing or modifying displayed content from a website temporarily.
  • Stealing user authentication information, such as session data.
  • Impersonating users to access information with their privileges, potentially compromising application security if an administrator is targeted.

Solution

Apply the relevant correction instructions as specified in this note. Detailed manual activities are required to update the Unified Rendering component of Web Dynpro ABAP. Refer to the following SAP Notes for specific updates:

  • SAP_BASIS 702: SAP Note 2097342, Unified Rendering for SAP_BASIS 702
  • SAP_BASIS 730: SAP Note 2154726, Unified Rendering for SAP_BASIS 730
  • SAP_BASIS 731: SAP Note 2156710, Unified Rendering for SAP_BASIS 731
  • SAP_UI 740: SAP Note 2154957, Unified Rendering for SAP_UI 740
  • SAP_UI 750: SAP Note 2207387, Unified Rendering for SAP_UI 750

Reason and prerequisites

Pages within Web Dynpro ABAP do not sufficiently encode output parameters, leading to a reflected cross-site scripting (XSS) vulnerability.

CVSS

Score 5.4 Vector: AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

References

Full note on SAP: SAP Support Launchpad note 2332977

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More