Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2019-0337Cross-Site Scripting (XSS) vulnerability in Java Proxy Runtime of SAP NetWeaver Process Integration, SAP security note 2789866

SAP Note 2789866
SAP Security Note
Medium priority

SAP security note 2789866, "[CVE-2019-0337] Cross-Site Scripting (XSS) Vulnerability in Java Proxy Runtime of SAP NetWeaver Process Integration", is a program error note. Below are the symptom and SAP recommended solution.

ComponentBasis Components > NetWeaver Process Integration (PI) > Connectivity > Java Proxy Runtime
CategoryProgram error
PriorityMedium priority
TypeSAP Security Note
StatusReleased for Customer on 26.01.2021

Description

Symptom

  • Non-permanent defacement or modification of displayed content on a website.
  • Theft of user authentication information, such as session data.
  • Impersonation of the user to access information with the same rights.

Solution

  • Code Changes: URL parameters are now properly encoded. Changes have been made to Outbound Java Proxy processing to address the issue.
  • Action Required: Apply the relevant support packages and patches referenced in this SAP Security Note.

CVSS

Score 6.1 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

References

Full note on SAP: SAP Support Launchpad note 2789866

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More