Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Cross-Site Scripting (XSS) vulnerability in IMP planning table / CRM-MKT-MPL-TPM-IMP, SAP security note 2347077

SAP Note 2347077
Medium priority

SAP security note 2347077, “Cross-Site Scripting (XSS) Vulnerability in IMP Planning Table / CRM-MKT-MPL-TPM-IMP”, is a program error note released on January 25, 2017. Below are the symptom, SAP recommended solution and the affected software components.

CategoryProgram error
PriorityCorrection with medium priority
StatusReleased for Customer
Released onJanuary 25, 2017

Description

Symptom

SAP Security Note 2347077 addresses a Cross-Site Scripting (XSS) vulnerability in the IMP planning table within the CRM-MKT-MPL-TPM-IMP component. This vulnerability arises from insufficient encoding of user-controlled inputs, potentially allowing attackers to execute malicious scripts.

  • Content Defacement: Attackers can temporarily modify or deface website content.
  • Session Theft: Steal user authentication information, including session data.
  • User Impersonation: Gain access to information with the same privileges as the targeted user.

Solution

Implement the support packages and patches referenced in this SAP Note to mitigate the vulnerability.

Affected components

  • TPM_IMP 200

Full note on SAP: SAP Support Launchpad note 2347077

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More