Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential disclosure of authentication information in XI, SAP security note 1414089

SAP Note 1414089

SAP security note 1414089, "Potential disclosure of authentication information in XI". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

SAP Note 1414089 addresses a Cross-Site Scripting (XSS) vulnerability in the remote ABAP API used by NetWeaver Process Integration Runtime Workbench (RWB). This vulnerability allows remote attackers to inject arbitrary scripts or HTML via a submission, potentially leading to unauthorized disclosure of authentication information.

Solution

To mitigate this vulnerability, apply the relevant support package that includes the provided patch. The patch ensures that HTTP input parameters are properly HTML-escaped before being returned to the client, thus preventing reflective XSS attacks.

References

Affected components

  • SAP_BASIS 640
  • SAP_BASIS 700
  • SAP_BASIS 701
  • SAP_BASIS 702
  • SAP_BASIS 710
  • SAP_BASIS 711

Full note on SAP: SAP Support Launchpad note 1414089

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More