Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

SAP Internet Communication Framework (BC-MID-ICF) Vulnerability

From: Ivan Buetler <ivan.buetler(at)csnc.ch>
Date: Wed Jun 27 2007 - 03:03:39 EDT


#############################################################
#
# COMPASS SECURITY ADVISORY http://www.csnc.ch/
#
#############################################################
#
# Product: Internet Communication Framework (BC-MID-ICF)
# Vendor: SAP
# Subject: Multiple XSS, HTML Injection
# Risk: High
# Effect: Remotely exploitable
# Author: Cyrill Brunschwiler (cyrill.brunschwiler@csnc.ch)
# Date: June, 17th 2007
#
#############################################################

Introduction:



Compass Security discovered multiple web application security flaws in the SAP Internet Communication Framework (BC-MID-ICF).

Vulnerable:



SAP Basis component 640 SP19 and lower
SAP Basis component 700 SP11 and lower

Not vulnerable:



Customers which registered a customized login error page for SIFC transactions (e.g. for default_host) may not suffer this vulnerability.

SAP Basis component 640 SP20
SAP Basis component 700 SP12

Vulnerability Management:



October 2006: Vulnerability found
October 2006: SAP Security notified
November 2007: SAP confirmation
April/May 2007: Patches available
June 2007: Compass Security Information

SAP Information Policy:



The information is available to registered SAP clients only (SAP Security Notes)

Patches:



Available at SAP (See SAP Note No. 1022102).
Do you need help?X

Description



The default login error page reflects unfiltered user input for multiple fields. Exploting the vulnerability will lead to so-called cross-site scripting (XSS).

XSS Ref: http://en.wikipedia.org/wiki/Cross-site_scripting

Cross-site scripting (XSS) is a type of computer security vulnerability typically found in web applications which allow code injection by malicious web users into the web pages viewed by other users. Examples of such code include HTML code and client-side scripts. An exploited cross-site scripting vulnerability can be used by attackers to bypass access controls such as the same origin policy. Recently, vulnerabilities of this kind have been exploited to craft powerful phishing attacks and browser exploits. Cross-site scripting was originally referred to as CSS, although this usage has been largely discontinued. Received on Wed Jun 27 11:39:18 2007

This archive was generated by hypermail 2.1.8 : Wed Jun 27 2007 - 11:40:04 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library