SAP WebDynpro Runtime XSS/CSS Injection Vulnerability
9 Apr. 2010
Summary
By exploiting this vulnerability, an internal or external attacker would be able perform attacks on the Organization's users through weaknesses in the SAP system.
Vulnerable Systems:
* SAP NetWeaver 2004 < SP21
* SAP NetWeaver 2004s < SP13
The WebDynpro Runtime suffers from a Cross-Site Scripting / CSS Injection vulnerability, which may enable remote attacks to perform different kind of attacks over SAP users.
No technical details about this issue are being distributed to the general public at this moment in order to provide enough time to affected companies to patch their systems and protect against the exploitation of the described vulnerability.
Patch Availability:
SAP has released SAP Note 1424863, which provides a patched version of the affected components.
This patch can be downloaded from: https://service.sap.com/sap/support/notes/1424863
Disclosure Timeline:
2009-11-24: Onapsis provides vulnerability information to SAP.
2009-11-24: SAP confirms reception of vulnerability submission.
2010-02-09: SAP releases security patch.
2010-02-10: Onapsis releases security advisory.