Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Cross-Site Scripting (XSS) vulnerability in Internet Sales, SAP security note 2273241

SAP Note 2273241
SAP Security Note
Medium priority

SAP security note 2273241, "Cross-Site Scripting (XSS) vulnerability in Internet Sales", is a program error note released on 12.04.2016. Below are the symptom and SAP recommended solution.

ComponentCustomer Relationship Management > Internet Sales > Technical Infrastructure
CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
Version10
StatusReleased for Customer
Released on12.04.2016

Description

Symptom

Internet Sales does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability. Some well-known impacts of XSS vulnerability include:

  • Non-permanently defacing or modifying displayed content from a web site
  • Stealing authentication information of the user, such as data relating to their current session
  • Impersonating the user and accessing all information with the same rights as the target user

Solution

The required input validation has been added to prevent a successful XSS attack. This SAP note contains Java Correction(s) for E-Commerce / Web Channel.

For further information about installing Java Patches, consult SAP Note 877887. Information about the patch strategy can be found in SAP Note 1546959.

CVSS

Score 6.1 Vector: AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Full note on SAP: SAP Support Launchpad note 2273241

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More