Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Security Note XSS in KM external links, SAP security note 1161008

SAP Note 1161008

SAP security note 1161008, "Security Note: XSS in KM external links". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

One can perform XSS attack in KM by providing as an external link target malicious scripting.

Solution

A. The issue is cleared in these deliveries:

  • Patch 2 for SP 22 of Content Management + Collaboration 6.0 640
  • SAP NetWeaver 04 SP 23 and up
  • SAP NetWeaver 7.0 (formerly named 2004s) SP 16 and up

B. Possible workaround before the release of the mentioned deliveries:

  • There is no workaround possible.
WarningThe fix will not affect the external links that are already created.

Reason and prerequisites

The text that is entered as an external link target is directly provided to the browser window that is opened when the link is accessed.

The fix affects:

  • Newly created external links.
  • External links whose target has been updated.

Affected components

  • SAP NetWeaver 04 up to SP 22
  • SAP NetWeaver 7.0 (formerly named 2004s) up to SP15

Full note on SAP: SAP Support Launchpad note 1161008

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More