Skip links
Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

WebGUI Java applet security redesign, SAP security note 1555523

Description

SAP WebGUI is a tool to emulate SAP GUI inside a browser and let SAP users drive the majority of SAP transactions written for SAP GUI with a Web browser. SAP WebGUI is based on the SAP ITS technology. In order to allow SAP users to do the same operations in WebGUI as in SAP GUI, WebGUI makes use of a trusted Java Applet to do local operations like i.e. file upload, file download, program execution and file/directory operation etc.

SAP did a redesign of the Java applet, to ensure that it can be used only inside a SAP environment and to let SAP users decide if they trust the applet and its origin or not. With this solution it is required to have the SAP cryptographic library (short SAP cryptolib) installed on the SAP application server or the standalone ITS 6.20 (see note 397175 for additional information on this library). For SAP ITS 6.20, copy the file (libsapcrypto.so on Linux, sapcrypto.dll on Windows) to the ITS “programs” directory on your ITS agate server (./sap/its/6.20/programs) and restart the ITS instances. In case the library has not been installed properly, the user will see a “Security warning” popup with the text: “The sapcrypto library is not installed. Please contact your system administrator”.

CVSS Information

CVSS Base Score: 6.8
CVSS Base Vector: AV:N/AC:M/AU:N/C:P/I:P/A:P

SAP provides this CVSS base score as an estimate of the risk posed by the issue reported in this note. This estimate does not take into account your own system configuration or operational environment. It is not intended to replace any risk assessments you are advised to conduct when deciding on the applicability or priority of this SAP security note. For more information, see the FAQ section at https://service.sap.com/securitynotes/.

Available fix and Supported packages

  • BC-FES-ITS | 620 | 620
  • SAP_BASIS | 46C | 46C
  • SAP_BASIS | 620 | 640
  • SAP_BASIS | 700 | 702
  • SAP_BASIS | 710 | 730
  • SAP_BASIS 700 | SAPKB70025 |
  • SAP_BASIS 710 | SAPKB71013 |
  • SAP_BASIS 701 | SAPKB70110 |
  • SAP_BASIS 711 | SAPKB71108 |
  • SAP_BASIS 720 | SAPKB72006 |
  • SAP_BASIS 702 | SAPKB70209 |
  • SAP_BASIS 730 | SAPKB73004 |
  • SAP_BASIS 46C | SAPKB46C63 |
  • SAP_BASIS 620 | SAPKB62071 |
  • SAP_BASIS 640 | SAPKB64029 |
  • SAP ITS 6.20 | SP040 | 000040
  • SAP KERNEL 6.40 32-BIT | SP370 | 000370
  • SAP KERNEL 6.40 32-BIT | SP372 | 000372
  • SAP KERNEL 6.40 32-BIT | SP374 | 000374
  • SAP KERNEL 6.40 32-BIT | SP376 | 000376
  • SAP KERNEL 6.40 32-BIT UNICODE | SP370 | 000370
  • SAP KERNEL 6.40 32-BIT UNICODE | SP372 | 000372
  • SAP KERNEL 6.40 32-BIT UNICODE | SP374 | 000374
  • SAP KERNEL 6.40 32-BIT UNICODE | SP376 | 000376
  • SAP KERNEL 6.40 64-BIT | SP370 | 000370
  • SAP KERNEL 6.40 64-BIT | SP372 | 000372
  • SAP KERNEL 6.40 64-BIT | SP374 | 000374
  • SAP KERNEL 6.40 64-BIT | SP376 | 000376
  • SAP KERNEL 6.40 64-BIT UNICODE | SP370 | 000370
  • SAP KERNEL 6.40 64-BIT UNICODE | SP372 | 000372
  • SAP KERNEL 6.40 64-BIT UNICODE | SP374 | 000374
  • SAP KERNEL 6.40 64-BIT UNICODE | SP376 | 000376
  • SAP KERNEL 6.40_EX2 32-BIT | SP370 | 000370
  • SAP KERNEL 6.40_EX2 32-BIT | SP372 | 000372
  • SAP KERNEL 6.40_EX2 32-BIT | SP374 | 000374

Affected component

    BC-FES-WGU
    SAP GUI for HTML

CVSS

Score: 0

PoC

Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.

URL

https://launchpad.support.sap.com/#/notes/1555523

TAGS

#

More to explorer

Special offer for SAP Security Udemy course!

$ 9.99

Join “SAP Security Core Concepts and Security Administration” which is part of the Blackhat course series.