SAP security note 1297256, “Security Note: Security Issues in Enterprise Service Builder”, is a note. Below are the symptom and SAP recommended solution.
Description
Symptom
- Several cross site scripting (XSS) vulnerabilities have been discovered in administrative Web interfaces of PI.
- Some servlets allow bypassing http-only cookie security.
- Some Exchange Profile parameters are saved as plain text in NWA.
- Reading and overwriting files using various administrative XI tools is possible.
- The password is contained in clear text in the HTML source code.
Solution
Why should customers apply the patch? This patch fixes the security issues mentioned with ESR, which could cause potential security threats such as XI administrative tools exhibiting several possibilities for script injection attacks via URL parameters.
Affected Versions:
- SAP NetWeaver 2004
- SAP NetWeaver 2004S
- SAP NetWeaver PI 7.1
- SAP EHP1 for SAP PI NetWeaver 7.1
Fixed Versions: all affected versions are fixed with the following support package levels:
- NW04 SP23
- NW04S SP18
- SAP NetWeaver 7.0 EHP1 SP02
- SAP NetWeaver PI 7.1 SP7
- SAP EHP1 for SAP NetWeaver PI 7.1 SP1
How to Apply the Patch: you can download the fixed versions from the Service Marketplace. Navigate to: Downloads, SAP Support Package, Enter by Application Group, SAP NetWeaver, Select the desired Release and SCA.
Reason and prerequisites
Problem Description:
XI administrative tools exhibit several possibilities for script injection attacks via URL parameters.
The Web interface of the servlet DocuBaseServlet returns a stack trace as well as all HTTP headers including cookie values.
In ESR, JEE application parameters can be set in NWA. Some parameters are not saved as desired in NWA.
Users having access to some services are able to read any file in the local file system, which is accessible by the SAP system user.
Any user having access to the exchange profile settings is able to retrieve the authentication credentials for all defined technical users.
Full note on SAP: SAP Support Launchpad note 1297256
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



