SAP security note 1466531, "Reflected cross-site scripting (BW document browser)". Below are the symptom and SAP recommended solution.
Description
Symptom
An attacker can manipulate the URL to change displayed data of another user without authorization and may access the authorization data of this user. The document browser of the BW ABAP Web runtime is also affected.
Solution
Import the appropriate Support Package into your BW system based on your SAP NetWeaver BW version:
- SAP NetWeaver BW 7.00: Import Support Package 25 (SAPKW70025) into your BW system. The Support Package is available when Note 1468668 “SAPBINews NW BI 7.0 ABAP SP25” is released for customers.
- SAP NetWeaver BW 7.01 (Enhancement Package 1): Import Support Package 08 (SAPKW70108) into your BW system. The Support Package is available when Note SAPBINews NW BI 7.01 ABAP SP08 is released for customers.
- SAP NetWeaver BW 7.02 (Enhancement Package 2): Import Support Package 05 (SAPKW70205) into your BW system. The Support Package is available when Note 1450990 “SAPBINews NW BI 7.02 ABAP SP05” is released for customers.
- SAP NetWeaver BW 7.10: Import Support Package 11 (SAPKW71011) into your BW system. The Support Package is available when Note 1453841 “SAPBINews NW BI 7.10 ABAP SP11” is released for customers.
- SAP NetWeaver BW 7.11: Import Support Package 05 (SAPKW71105) into your BW system. The Support Package is available when Note 1392433 “SAPBINews NW BI 7.11 ABAP SP05” is released for customers.
- SAP NetWeaver BW 7.20: Import Support Package 04 (SAPKW72004) into your BW system. The Support Package is available when Note 1436250 “SAPBINews NW BI 7.20 ABAP SP04” is released for customers.
Reason and prerequisites
Reflected cross-site scripting can be triggered due to inadequate output coding via APIs in the document browser. As a result, the content of a web page can be manipulated when a manipulated link is called. An attacker can use reflected cross-site scripting to steal the logon information of the current session of a victim. The attacker can then use this information to impersonate the victim and access the application with the same rights as the user who was attacked. If the target of the attack is a user with administrative rights, all of the application data may be compromised.
Full note on SAP: SAP Support Launchpad note 1466531
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
