Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential disclosure of authentication information, SAP security note 1442580

SAP Note 1442580

SAP security note 1442580, "Potential disclosure of authentication information". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

The application ‘Alert-Configuration’ within XI/PI Runtime Workbench (RWB) can be exploited by a malicious user to obtain authentication information from other legitimate users.

Solution

The fix is available with the assigned Support Packages for the respective releases and is included starting from SAP_BASIS 7.30.

Reason and prerequisites

Certain pages within the RWB Alert-Configuration do not adequately encode input parameters, leading to reflected cross-site scripting issues and cross-domain redirection vulnerabilities.

Reflected XSS can be utilized to steal another user’s authentication information, such as session data, or to non-permanently deface a website. An attacker with access to this data could impersonate the user and access all information with the same privileges as the target user. If an administrator is impersonated, it may result in a full compromise of the application’s security.

Affected releases and support package levels:

  • SAP BASIS 6.40 until SP26
  • SAP BASIS 7.00 until SP22
  • SAP BASIS 7.01 until SP07
  • SAP BASIS 7.02 until SP04
  • SAP BASIS 7.03 until SP01
  • SAP BASIS 7.10 until SP10
  • SAP BASIS 7.11 until SP05
  • SAP BASIS 7.20 until SP03

References

  • 1459565 – SAP EHP1 FOR SAP NETWEAVER PI 7.1 SP05
  • 888889 – Automatic checks for security notes using RSECNOTE (outdated)

Full note on SAP: SAP Support Launchpad note 1442580

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More