Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

XSS Vulnerabilities in HTMLB, SAP security note 2173184

SAP Note 2173184

SAP security note 2173184, "XSS Vulnerabilities in HTMLB." Below are the symptom, SAP recommended solution and the affected software components.

ComponentEnterprise Portal > SAP Enterprise Portal Development Kit (PDK) > HTMLB Business for Java

Description

Symptom

HTMLB can be abused by an attacker, allowing them to modify displayed application content.

UI elements within HTMLB do not sufficiently encode input parameters, resulting in a reflected cross-site scripting (XSS) issue. This vulnerability can be exploited to non-permanently deface or modify displayed content on a website. Additionally, attackers may steal users’ authentication information, leading to potential impersonation and unauthorized access.

Solution

The issue is fixed by applying the HTMLB for Java patch. Follow these steps:

  • Download HTMLB for Java Patches: all patches are available on the SAP Service Marketplace.
  • Release Specific Details: depending on your NetWeaver version, deploy the appropriate Support Package Archive (SCA) using the Software Deployment Manager (SDM).
  • Recommendations: for portal usage, apply the latest relevant EPBC2 or EPBASIS.SCA available on the Service Marketplace. For portal independent usage, apply the latest FRAMEWORK.SCA from the Service Marketplace.

CVSS

Score 4.3 / 10

References

Affected components

  • Enterprise Portal > SAP Enterprise Portal Development Kit (PDK) > HTMLB Business for Java

Full note on SAP: SAP Support Launchpad note 2173184

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More