SAP security note 2369469, "Cross-Site Scripting (XSS) Vulnerability in SAP Enterprise Portal Navigation". Below are the symptom and SAP recommended solution.
Description
Symptom
SAP Enterprise Portal Navigation does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to:
- Non-permanently deface or modify displayed content on a website
- Steal authentication information of users, such as session data
- Impersonate users and access information with the same rights as the target user
Solution
Encoding has been added to request parameters to mitigate the XSS vulnerability. To apply the fix, ensure you install the appropriate Support Package Patch (SP Patch Level) as listed below.
CVSS
Score 6.1 Vector: AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
References
Full note on SAP: SAP Support Launchpad note 2369469
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
