SAP security note 1322098, “Security Note: Cross-Site Scripting Vulnerab. in UDDI Client”. Below are the symptom and SAP recommended solution.
Description
Symptom
This security note describes a prevention of a Cross-Site Scripting Vulnerability in the UDDI Client. The UDDI Client is part of NetWeaver Application Server Java (AS Java). As such, it is part of several other NetWeaver components such as the Exchange Infrastructure. The affected version is 640, 700, and 701.
The UDDI Client is a tool that implements the Universal Description Discovery and Integration (UDDI) functions based on the UDDI v2.0 specification. The UDDI Client is started automatically when accessing it and can be reached via the URL http://<host>:<port>/uddiclient.
For more information on the UDDI Client, see the SAP Documentation or search SAP Help Portal for “UDDI Client”.
Solution
Apply the support package that contains the fix as stated below (or a higher one). Support Packages are available from the SAP Service Marketplace. Alternatively, you can apply a patch on an existing installation based on an older SP level.
Reason and prerequisites
This vulnerability can result in a wide range of attacks that may impact availability and confidentiality.
References
- Update 1 to Security Note 1322098 (BC-ESI-UDDI)
Full note on SAP: SAP Support Launchpad note 1322098
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
