SAP security note 2272211, "Update of SAPUI5 version in SAP HANA due to security note 2204160". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
SAP HANA includes SAPUI5 for applications based on the SAP HANA Extended Application Services classic model. A vulnerability in SAPUI5 allows attackers to modify displayed application content without authorization and potentially obtain authentication information from legitimate users.
Solution
Update SAPUI5 to version 1.28.23 within SAP HANA:
- For SPS10: Apply revision 102.04
- For SPS11: Apply revision 111 or later
The SAP HANA Extended Application Services advanced model is not affected by this vulnerability.
For more detailed information, refer to SAP Security Note 2204160.
Reason and prerequisites
The Support Tool within SAPUI5 does not sufficiently encode input parameters, leading to a reflected cross-site scripting (XSS) vulnerability. This can allow attackers to:
- Deface or modify displayed content on your web applications.
- Steal authentication information from users, potentially allowing attackers to impersonate users with the same access rights.
Affected Component: SAP HANA Extended Application Services (HAN-AS-XS)
CVSS
Score 4.3 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N
References
Affected components
- HDB: Version 1.00
Full note on SAP: SAP Support Launchpad note 2272211
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
