SAP security note 986992, "ILION Research Labs reported SAP ITS XSS exploit on Bugtraq". Below are the symptom and SAP recommended solution.
Description
Symptom
On Bugtraq, ILION Research Labs reported a Cross-Site Scripting (XSS) vulnerability in SAP Internet Transaction Server (ITS). The report can be accessed on SecurityFocus.
This SAP note informs SAP customers about SAP's view of the reported vulnerability.
Solution
- ITS 6.20: apply the most current SAP ITS 6.20 patch level from the Service Marketplace.
- SAP NetWeaver 2004: apply SAP Kernel patch 151 or higher as described in SAP Note 986444.
Reason and prerequisites
ITS 6.10 is affected by the issue. This release is out of maintenance since 31.12.2004, and SAP no longer creates patches for ITS 6.10. SAP highly recommends all customers upgrade ITS 6.10 installations to the latest ITS 6.20 patch level.
ITS 6.20 installations are affected by the reported exploit if the patch level is 17 or lower. SAP released patch level 18 in May 2005; customers who apply patches regularly should not be affected. The current patch level for ITS 6.20 is 22.
SAP NetWeaver 2004 with integrated ITS is affected by the ~urlmime issue up to SAP Kernel patch 150.
References
Full note on SAP: SAP Support Launchpad note 986992
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




