Home > SAP software/management News > Flaw opens SAP Web Application Server to phishing scams
SAP software/management News:
EMAIL THIS

Flaw opens SAP Web Application Server to phishing scams

By Robert Westervelt, News Editor
10 Nov 2005 | SearchSAP.com

SAP news, tips and expert advice
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

A South American security firm has discovered multiple vulnerabilities in the SAP Web Application Server that could be exploited to conduct a phishing scam and cross-site scripting attacks.

The flaws were discovered in versions 6.10, 6.20, 6.40 and 7.00, and affect the business service provider (BSP) runtime of the Web application server.

The firm that discovered the vulnerabilities, Cybsec SA, which has offices in Panama, Ecuador and Argentina, has given the flaws medium to high threat classifications. SAP was notified in September and had a patch developed last month. The patch is being released this week in coordination with the advisory, according to Leandro Meiners, a Cybsec researcher who discovered the flaws.

Topic center:
SAP security

"SAP Web Application Server was found to be vulnerable to JavaScript injection, allowing for cross-site scripting attacks," Meiners wrote in a public advisory.

Left open, the flaws could allow an attacker to execute arbitrary HTML and script code in a user's browser. Users could be tricked into visiting a malicious Web site by following a link with a trusted host name, according to Cybsec.

The link "will logout the user from the application (sap-sessioncmd=close), even if not logged in, and redirect to the attacker site," Meiners said.

A partial fix to the vulnerabilities can be found in SAP Note 887323, which indicates which service packs to apply, according to Cybsec.

SAP is also advising customers in SAP Note 887322, to disable the sap-exiturl parameter in older 6.10 releases and 6.20 prior to service pack 54. In newer 6.20 and 7.00 releases, the parameter will be submitted to a customer-configured white list, according to the Cybsec advisory.

Cybsec SAP advisories:

  • Security advisory: Multiple XSS in SAP WAS
  • Security advisory: Phishing Vector in SAP WAS
  • Security advisory: HTTP Response Splitting in SAP WAS

    Tags: SAP security administrationVIEW ALL TAGS

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



    RELATED CONTENT
    SAP security administration
    Granting user access to cost centers through SAP authorization objects
    The top SAP advice from the experts in 2009
    SAP TechEd 2009 Phoenix: SearchSAP.com Special Report
    How to stop SAP users from displaying SAP HR tables content
    Locating user email addresses in SAP SU01 transaction code
    How to map multiple SAP roles and profiles
    Viewing SAP transaction codes and profiles
    Managing SAP user access and password expirations
    Can SAP developer include authority check for S_TCODE in a called transaction?
    Cisco and SAP integrate technologies to create data privacy application

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



  • SAP Training & Employment
    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    SEARCH 
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2000 - 2010, TechTarget | Read our Privacy Policy
    SearchSAP.com is a search service provided by TechTarget and is completely
    independent of and not affiliated with SAP AG.
      TechTarget - The IT Media ROI Experts