Advisory
A note with CVSS 6.1 for component BC-CTS-DTR was released by SAP on 14.06.2022. The correction/advisory 3197927 was described with "[CVE-2022-29618] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Development Infrastructure (Design Time Repository)" and affects the system type Java.
A workaround exists, according to SAP Security Advisory team. It is advisable to implement the correction as part of maintenance.
The vulnerability addressed is cross-site scripting (xss) within Java.
Risk specification
SAP NetWeaver Design Time Repository (DTR) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
Solution
The URL parameters are now properly encoded to prevent a successful XSS attack. Although an alternative solution exists, it is advisable to apply the correction! This is the workaround, which was suggested by the SAP security experts: "Cross-site scripting/request forgery filter engine on IDS/IPS/firewall systems. ".
Affected System
SAP Netweaver Application Server Java is part of the SAP NetWeaver Application Platform. It provides the complete infrastructure for deploying and running Java applications.
- The AS Java Home: SAP Netweaver Application Server Java wiki
- A dedicated SAP NetWeaver 7.40 Application Server for Java Security Guide exists.
The advisory is valid for
- DI_DTR 7.30 2
- DI_DTR 7.31 2
- DI_DTR 7.40 2
- DI_DTR 7.50 3
