Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

XSS in CBS web UI, SAP security note 1456175

SAP Note 1456175SAP Security NoteHigh priority

SAP security note 1456175, "XSS in CBS web UI", released on September 14, 2010. Below are the symptom, SAP recommended solution and the affected software components.

ComponentBasis Components > Change and Transport System > Component Build Server & Component Infrastructure (BC-CTS-CBS)
PriorityCorrection with high priority
TypeSAP Security Note
StatusReleased for Customer
Released onSeptember 14, 2010

Description

Symptom

A Cross-Site Scripting (XSS) vulnerability has been identified in the CBS web UI. A malicious user could exploit this vulnerability to modify displayed application content without authorization and potentially steal authentication information from other users. This could lead to session hijacking, allowing an attacker to impersonate legitimate users and gain unauthorized access to sensitive information. If an administrator’s credentials are compromised, the entire application’s security could be severely impacted.

Solution

To address this vulnerability, it is recommended to deploy the latest patch for SAPDEVINF.SCA.

References

Affected components

  • DI_CBS 6.40
  • SAP_DEVINF 6.40

Full note on SAP: SAP Support Launchpad note 1456175

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More