Security Holes Discovered In SAP NetWeaver Web App Platfrom

Cyber security vulnerabilities have been discovered in several components of SAP’s NetWeaver platform by security firm Positive Technologies.

The flaws in NetWeaver, which acts as an interoperable platform for building web-based apps that integrate business processes and databases from numerous sources, were found to enable hackers to carry out activities that could potentially lead to the compromise of a company’s IT systems.

Cross-site scripting (XSS) vulnerabilities were found in the SAP Enterprise Portal Navigation (CVSSv3 score 6.1) and SAP Enterprise Portal Theme Editor (three flaws with CVSSv3 scores 5.4, 6.1, and 6.1). While a vulnerability that enables arbitrary file upload was found in SAP’s NetWeaver Log Viewer.

SAP NewWeaver woes

SAP NetWeaver platformThe XSS flaws opens up the components of SAP Enterprise Portal to attackers, who could use them to gain access to a user’s session tokens, login credentials, and other sensitive browser information. From there Positive Technologies noted an attacker could perform arbitrary actions on the victim’s behalf, rewrite HTML page content and intercept keystrokes.

With the NetWeaver Log Viewer flaw, the consensuses of a successful cyber attack are even worse as a file upload could compromise an entire targeted systems or database as arbitrary code can be uploaded and executed on a server, rather than an isolated system, leading to attacks on back-end systems, such as database platforms like SAP’s own HANA.

“Large companies all over the world use SAP to manage financial flows, product lifecycle, relationships with vendors and clients, company resources, procurement, and other critical business processes. It is vital to protect the information stored in SAP systems as any breach of confidential information could have a devastating impact on the business.” said Dmitry Gutsko, head of the business system security unit at Positive Technologies.

Users of the NetWeaver 7.31 are advised to ensure their system has the latest update and use tool certified for integration with SAP NetWeaver.

While a patch may take care of the flaws, the security holes are not great for SAP’s reputation, especially since it had to recently rush to squash security bugs in its HANA database platform.

Quiz. Are you a security guru?

Roland Moore-Colyer

As News Editor of Silicon UK, Roland keeps a keen eye on the daily tech news coverage for the site, while also focusing on stories around cyber security, public sector IT, innovation, AI, and gadgets.

Recent Posts

Tesla Recalls 46,000 Cybertrucks Over ‘Crash Risk’ Faulty Trim

All Cybertrucks manufactured between November 2023 and February 2025 recalled over trim that can fall…

1 day ago

Elon Musk Issued Summons By SEC Over Failure To Disclose Twitter Stake

As Musk guts US federal agencies, SEC issues summons over Elon's failure to disclose ownership…

1 day ago

Alphabet Spins Out Taara To Challenge Musk’s Starlink

Moonshot project Taara spun out of Google, uses lasers and not satellites to provide internet…

1 day ago

Pebble Creator Debuts New Watches As ‘Labour Of Love’

Pebble creator launches two new PebbleOS-based smartwatches with 30-day battery life, e-ink screens after OS…

3 days ago

Amazon Loses Appeal To Record EU Privacy Fine

Amazon loses appeal in Luxembourg's administrative court over 746m euro GDPR fine related to use…

3 days ago

Nvidia, xAI Join BlackRock AI Infrastructure Project

Nvidia, xAI to participate in project backed by BlackRock, Microsoft to invest $100bn in AI…

3 days ago