SAP security note 2377626, "Cross-Site Scripting (XSS) Vulnerability in SAP Enterprise Portal Theme Editor". Below are the symptom and SAP recommended solution.
Description
Symptom
A vulnerability has been identified in the _designservice of the SAP Enterprise Portal Theme Editor. Insufficient encoding of user-controlled inputs allows attackers to execute Cross-Site Scripting (XSS) attacks.
Potential impacts include:
- Defacing or modifying website content.
- Stealing user authentication information, including session data.
- Impersonating users to access information with their privileges.
Solution
Apply the relevant Support Package Patches to address the vulnerability.
CVSS
Score 6.1 Vector: AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Full note on SAP: SAP Support Launchpad note 2377626
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
