Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

ITS XSS vulnerability on page generated by HTTP handler, SAP security note 1581156

SAP Note 1581156
SAP Security Note
High priority

SAP security note 1581156, “ITS: XSS vulnerability on page generated by HTTP handler”, is a program error note released on July 10, 2012. Below are the symptom, SAP recommended solution and the affected software components.

ComponentSAP Internet Transaction Server (BC-FES-ITS)
CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
StatusReleased for Customer
Released onJuly 10, 2012
LanguageEnglish

Description

Symptom

A JavaScript Cross-Site Scripting (XSS) vulnerability exists on the HTML page generated by the HTTP handler of the ITS services. This vulnerability affects the services of the NetWeaver integrated ITS that use the current version of the HTTP handler CL_HTTP_EXT_ITS. An attacker could exploit this vulnerability to execute arbitrary JavaScript code in the context of a user’s browser, potentially leading to unauthorized actions or data disclosure.

Solution

To address this vulnerability, import the most current Basis Support Package for your NetWeaver system.

Reason and prerequisites

Ensure the following SAP Notes are implemented to maintain system integrity: 1521808 (ITS: Follow-up tasks for XSRF framework), 1459135 (SAP GUI for HTML: URL OK code strings w/ over 200 characters), 1465767 (Logon user exit SUSR0001 not called), 1571684 (Protect against cross-site request forgery for ITS mobile Services), 1702575 (SAP GUI for HTML: Connection closed immediately after start), 1475285 (SAP GUI for HTML: Parameters such as ~nosplash are ignored), 1552922 (SAP GUI for HTML: Minor corrections in the spring of 2011), 1708362 (SAP GUI for HTML: Correction instructions for SAP Note 1571684), and 1410968 (SAP GUI for HTML: Security warning during HTTPS request).

Affected components

  • SAP_BASIS: 6.40
  • SAP_BASIS: 7.00 to 7.02
  • SAP_BASIS: 7.10 to 7.30

Full note on SAP: SAP Support Launchpad note 1581156

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More