SAP security note 2344441, “Cross-Site Scripting (XSS) vulnerability in PI Message Display Tool.” Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A Cross-Site Scripting (XSS) vulnerability has been identified in the PI Message Display Tool. This vulnerability arises because the tool does not sufficiently encode user-controlled inputs, allowing malicious scripts to be executed in the context of the user’s browser.
The PI Message Display Tool fails to properly encode user inputs, resulting in the possibility of XSS attacks. This can lead to:
- Non-permanent defacement or modification of displayed content on a website.
- Theft of authentication information, such as session data.
- Impersonation of the user, granting access to information with the same privileges as the target user.
Solution
This vulnerability has been addressed in the Support Packages and Patches referenced by this SAP Security Note. It is recommended to apply the relevant patches to mitigate the risk.
CVSS
Score 6.1/10 Vector: AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Affected components
- MESSAGING SYSTEM SERVICE: Versions 7.10 to 7.50
- SAP_XIAF: Versions 7.00 to 7.02
Full note on SAP: SAP Support Launchpad note 2344441
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




