Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Cross-Site Scripting (XSS) vulnerability in SAP Enterprise Portal Theme Editor, SAP security note 2372204

SAP Note 2372204
Medium priority

SAP security note 2372204, "Cross-Site Scripting (XSS) vulnerability in SAP Enterprise Portal Theme Editor", is a program error note released on 10.01.2017. Below are the symptom and SAP recommended solution.

ComponentEP-PIN-TOL
CategoryProgram error
PriorityCorrection with medium priority
Version5
StatusReleased for Customer
Released on10.01.2017

Description

Symptom

Styles Integrity Test Component does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability.

Impacts of XSS Vulnerability:

  • Non-permanently deface or modify displayed content from a website.
  • Steal authentication information of the user, such as data relating to their current session.
  • Impersonate the user and access all information with the same rights as the target user.

Solution

Output encoding functions have been implemented to address the vulnerability.

CVSS

Score 6.1 Vector: AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

References

Full note on SAP: SAP Support Launchpad note 2372204

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More