SAP security note 1438191, "Unauthorized modification of displayed content- SOAP Adapter". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
SOAP Adapter Helper servlet has a vulnerability to reflected Cross-Site Scripting (XSS) attacks. An attacker may specify an unrecognized value of an input parameter with malicious script commands, causing these commands to execute in the user’s browser.
Solution
Please apply the corresponding patch listed below.
Reason and prerequisites
The SOAP Adapter Helper servlet does not sufficiently encode input parameters, making it vulnerable to reflected cross-site scripting attacks. An attacker can present a malicious link to a victim, and clicking it can execute malicious scripts in the user’s browser. This compromises the user’s security context, including browser cookies and cache objects. It can also cause the victim’s browser to navigate to URLs on the vulnerable site, allowing the attacker to intrude into the user’s security context.
Reflected cross-site scripting can be used to steal another user’s authentication information, such as session data. An attacker with access to this data could impersonate the user and access all information with the same rights. If an administrator is impersonated, the application’s security could be fully compromised.
References
- Procedure to deactivate SOAP Adapter and JPR applications
- Briefing at Black Hat conference on August 4th, 2011
- SAP EhP1 for XI on Netweaver 7.00 SP09
- NW04s XI Support Package Stack 24
- SAP EhP2 for Netweaver 7.00 SP07
- SAP EhP1 for XI on Netweaver 7.00 SP08
- NW04s XI Support Package Stack 23
- SAP EHP1 FOR SAP NETWEAVER PI 7.1 SP05
Affected components
- 7.10 – SP6 patch level 39 or less
- 7.10 – SP7 patch level 42 or less
- 7.10 – SP8 patch level 22 or less
- 7.10 – SP9 patch level 6 or less
- 7.11 – EHP1 SP2 patch level 18 or less
- 7.11 – EHP1 SP3 patch level 16 or less
- 7.11 – EHP1 SP4 patch level 5 or less
Full note on SAP: SAP Support Launchpad note 1438191
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
