Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Cross-Site Scripting (XSS) vulnerability in BIWorkspace, SAP security note 2249634

SAP Note 2249634

SAP security note 2249634, “Cross-Site Scripting (XSS) vulnerability in BIWorkspace”, is a note released on 09.08.2016. Below are the symptom and SAP recommended solution.

ComponentBusiness intelligence solutions > Business intelligence platform > InfoView, BI launch pad
Released on09.08.2016

Description

Symptom

BIWorkspace does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability. This allows an attacker to modify displayed application content for legitimate users without authorization.

Exploiting this vulnerability can lead to:

  • Non-permanently defacing or modifying displayed content on a website
  • Stealing user authentication information, such as session data
  • Impersonating the user and accessing information with the same rights as the target user

Solution

This vulnerability is fixed in the patches listed below in the Support Package Patches section.

CVSS

Score 6.1 Vector: AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

References

Full note on SAP: SAP Support Launchpad note 2249634

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More