Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Security Note Cross-Site Scripting Vulnerab. in UDDI Client, SAP security note 1322098

SAP Note 1322098

SAP security note 1322098, “Security Note: Cross-Site Scripting Vulnerab. in UDDI Client”. Below are the symptom and SAP recommended solution.

Description

Symptom

This security note describes a prevention of a Cross-Site Scripting Vulnerability in the UDDI Client. The UDDI Client is part of NetWeaver Application Server Java (AS Java). As such, it is part of several other NetWeaver components such as the Exchange Infrastructure. The affected version is 640, 700, and 701.

The UDDI Client is a tool that implements the Universal Description Discovery and Integration (UDDI) functions based on the UDDI v2.0 specification. The UDDI Client is started automatically when accessing it and can be reached via the URL http://<host>:<port>/uddiclient.

For more information on the UDDI Client, see the SAP Documentation or search SAP Help Portal for “UDDI Client”.

Solution

Apply the support package that contains the fix as stated below (or a higher one). Support Packages are available from the SAP Service Marketplace. Alternatively, you can apply a patch on an existing installation based on an older SP level.

Reason and prerequisites

This vulnerability can result in a wide range of attacks that may impact availability and confidentiality.

References

Full note on SAP: SAP Support Launchpad note 1322098

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More