Medium priority
SAP security note 2347077, “Cross-Site Scripting (XSS) Vulnerability in IMP Planning Table / CRM-MKT-MPL-TPM-IMP”, is a program error note released on January 25, 2017. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
SAP Security Note 2347077 addresses a Cross-Site Scripting (XSS) vulnerability in the IMP planning table within the CRM-MKT-MPL-TPM-IMP component. This vulnerability arises from insufficient encoding of user-controlled inputs, potentially allowing attackers to execute malicious scripts.
- Content Defacement: Attackers can temporarily modify or deface website content.
- Session Theft: Steal user authentication information, including session data.
- User Impersonation: Gain access to information with the same privileges as the targeted user.
Solution
Implement the support packages and patches referenced in this SAP Note to mitigate the vulnerability.
Affected components
- TPM_IMP 200
Full note on SAP: SAP Support Launchpad note 2347077
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




