Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Multiple security vulnerabilities in SAP NetWeaver BSP Logon, SAP security note 2195595

SAP Note 2195595SAP Security NoteHigh priority

SAP security note 2195595, "Multiple Security Vulnerabilities in SAP NetWeaver BSP Logon", is a program error note released on 13.10.2015. Below are the symptom and SAP recommended solution.

CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
Version3
StatusReleased for Customer
Released on13.10.2015

Description

Symptom

Multiple security vulnerabilities have been discovered in BSP (Business Server Pages) applications:

  • Cross Site Scripting (XSS): The application is vulnerable to XSS attacks.
  • URL Redirection: An attacker can host external resources in an iframe using the URL path when the user is authenticated. (CVSS Score: 4.3)

Solution

Please update SAP Basis to an SP or release where the issue is fixed. Refer to the Support Package section below for details and available patches.

Reason and prerequisites

The security vulnerabilities are found in the class CL_BSP_LOGIN_HANDLER used in BSP applications. This class is not protected against XSS and iframe-related security vulnerabilities. The obsolete class CL_BSP_LOGIN_HANDLER is no longer maintained and developed and will not be included in new SAP systems in the future.

CVSS

Score 4.3 / 10 Vector: AV:N/AC:M/PR:N/UI:N/S:U/C:N/I:P/A:N

Full note on SAP: SAP Support Launchpad note 2195595

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More