Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Update of SAPUI5 version in SAP HANA due to security note 2204160, SAP security note 2272211

SAP Note 2272211

SAP security note 2272211, "Update of SAPUI5 version in SAP HANA due to security note 2204160". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

SAP HANA includes SAPUI5 for applications based on the SAP HANA Extended Application Services classic model. A vulnerability in SAPUI5 allows attackers to modify displayed application content without authorization and potentially obtain authentication information from legitimate users.

Solution

Update SAPUI5 to version 1.28.23 within SAP HANA:

  • For SPS10: Apply revision 102.04
  • For SPS11: Apply revision 111 or later

The SAP HANA Extended Application Services advanced model is not affected by this vulnerability.

For more detailed information, refer to SAP Security Note 2204160.

Reason and prerequisites

The Support Tool within SAPUI5 does not sufficiently encode input parameters, leading to a reflected cross-site scripting (XSS) vulnerability. This can allow attackers to:

  • Deface or modify displayed content on your web applications.
  • Steal authentication information from users, potentially allowing attackers to impersonate users with the same access rights.

Affected Component: SAP HANA Extended Application Services (HAN-AS-XS)

CVSS

Score 4.3 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

References

Affected components

  • HDB: Version 1.00

Full note on SAP: SAP Support Launchpad note 2272211

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More