Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Security Note Cross site scripting via CurrentFocusID, SAP security note 1321116

SAP Note 1321116

SAP security note 1321116, "Security Note: Cross site scripting via CurrentFocusID", is a note. Below are the symptom, SAP recommended solution and reason and prerequisites.

Description

Symptom

WebDynpro applications have a security vulnerability that allows Cross Site Scripting (XSS) via CurrentFocusID.

Solution

The issue has been resolved by properly escaping the CurrentFocusID on the server side. The fix is available in the upcoming Support Packages for the following releases:

  • NW 6.40, SP24 and above
  • NW 7.00, SP19 and above
  • NW 7.01, SP04 and above
  • NW 7.02, SP00 and above
  • NW 7.10, SP08 and above
  • NW 7.11, SP02 and above

Additionally, patches are available for the following releases:

  • NW 7.00, SP15 (Refer to note 1138102) – SAPJTECHS15P patch level 15, SAPJTECHF15P patch level 14
  • NW 7.00, SP16 (Refer to note 1226726) – SAPJTECHS16P patch level 16, SAPJTECHF16P patch level 14
  • NW 7.00, SP17 (Refer to note 1248027) – SAPJTECHS17P patch level 06, SAPJTECHF17P patch level 05
  • NW 7.00, SP18 (Refer to note 1291752) – SAPJTECHS18P patch level 3, SAPJTECHF18P patch level 3
  • NW 7.11, SP01 (Refer to upcoming notes)

Note 1: The note number and patch number for NW 7.11, SP01 will be updated once available.

Note 2: For NW 6.40 SP24 and above, the software archive is delivered as a .SAR file. In the download region, look for the file with the description "J2EERT24" (For SP24).

Reason and prerequisites

In WebDynpro, the CurrentFocusID sent from the client was not properly escaped on the server side before it was sent back to the client. This vulnerability allows an attacker to inject malicious JavaScript code into the response of WebDynpro applications.

Full note on SAP: SAP Support Launchpad note 1321116

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More