SAP security note 2249634, “Cross-Site Scripting (XSS) vulnerability in BIWorkspace”, is a note released on 09.08.2016. Below are the symptom and SAP recommended solution.
Description
Symptom
BIWorkspace does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability. This allows an attacker to modify displayed application content for legitimate users without authorization.
Exploiting this vulnerability can lead to:
- Non-permanently defacing or modifying displayed content on a website
- Stealing user authentication information, such as session data
- Impersonating the user and accessing information with the same rights as the target user
Solution
This vulnerability is fixed in the patches listed below in the Support Package Patches section.
CVSS
Score 6.1 Vector: AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
References
Full note on SAP: SAP Support Launchpad note 2249634
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
