SAP Security Note
High priority
SAP security note 1018575, "Cross-site scripting (XSS) using the IGS", was released on 08.10.2009. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Cross-site scripting (XSS)
Solution
Please install IGS 6.40 patch 18 or IGS 7.00 patch 8.
Reason and prerequisites
You have defined an HTTP listener and have specified HTTP administration access to your Internet Graphics Server (IGS). The content of HTTP parameters is returned without further checking.
CVSS
Score 0
References
- 959358 – IGS HTTP administration is not possible
- 862169 – Deactivating HTTP access to the IGS
- 1072557 – Vulnerabilities disclosed on July 5, 2007
- 1018277 – IGS 6.40 patch 18
- 1017387 – IGS 7.00 patch 8
Affected components
- BC-FES-IGS 6.40
- BC-FES-IGS 7.00
Full note on SAP: SAP Support Launchpad note 1018575
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



