SAP security note 1443659, "XSS in ShowMemLog & ControlLog". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Several cross-site scripting (XSS) vulnerabilities have been discovered in the administrative web interfaces of ESR.
Solution
Apply the provided patch to fix the security issues, which prevent script injection attacks via URL parameters in XI administrative tools.
Affected components
- SAP NetWeaver 2004
- SAP NetWeaver 2004S
- SAP NetWeaver PI 7.1
- SAP EHP1 for SAP PI NetWeaver 7.1
Full note on SAP: SAP Support Launchpad note 1443659
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
