Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Cross-Site Scripting (XSS) vulnerability in SAP CRM IPC Pricing, SAP security note 2481262

SAP Note 2481262
Medium priority

SAP security note 2481262, "Cross-Site Scripting (XSS) vulnerability in SAP CRM IPC Pricing", is a program error note released on August 8, 2017. Below are the symptom and SAP recommended solution.

CategoryProgram error
PriorityMedium priority
StatusReleased for Customer
Released onAugust 8, 2017

Description

Symptom

IPC Pricing does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability.

Impacts of XSS Vulnerability:

  • Non-permanently deface or modify displayed content from a website.
  • Steal authentication information of the user, such as data relating to their current session.
  • Impersonate the user and access all information with the same rights as the target user.

Solution

The code has been removed, preventing a successful XSS attack as the code is obsolete. This SAP note contains Java Corrections for E-Commerce / Web Channel. Apply the patches as mentioned in the "Support Packages & Patches" section.

For further information about installing Java Patches, consult Note 877887. Information about the patch strategy can be found in Note 1546959.

Reason and prerequisites

Reason: IPC Pricing does not sufficiently encode INPUT parameters, resulting in a reflected cross-site scripting issue.

CVSS

Score 6.1 Vector: AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

References

Full note on SAP: SAP Support Launchpad note 2481262

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More