SAP security note 2493099, “Multiple Security Vulnerabilities in SAP SRM Live Auction Application”, is a note released on 08.08.2017. Below are the symptom and SAP recommended solution.
Description
Symptom
Multiple security vulnerabilities have been discovered in the SAP SRM Live Auction Application.
1. Cross-Site Scripting (XSS)
The Live Auction smoke test application does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability.
- Non-permanently deface or modify displayed content from a website.
- Steal authentication information of the user, such as data relating to their current session.
- Impersonate the user and access all information with the same rights as the target user.
CVSS v3 Base Score: 6.1 / 10 (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
2. Information Disclosure
Under certain conditions, the Live Auction application allows an attacker to access information that would otherwise be restricted.
- Loss of information and system configuration confidentiality.
- Information gathering for further exploits and attacks.
CVSS Score: 4.3 (NLLN | U | LNN)
Solution
- Remove Vulnerable Pages: Vulnerable and obsolete smoke test pages are removed from the LAC application.
- Apply Latest Patch: Implement the latest LAC patch to resolve the issue.
Full note on SAP: SAP Support Launchpad note 2493099
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
