SAP security note 2417020, "Cross-Site Scripting (XSS) Vulnerability in SAP NetWeaver Business Client for HTML". Below are the symptom and SAP recommended solution.
Description
Symptom
SAP NetWeaver Business Client for HTML has a Cross-Site Scripting (XSS) vulnerability due to insufficient encoding of user-controlled inputs. This vulnerability can lead to:
- Defacement or modification of displayed content on a web site.
- Theft of user authentication information, such as session data.
- Impersonation of users to access information with the same privileges.
Solution
Implement this SAP Security Note to address and mitigate the XSS vulnerability.
CVSS
Score 6.1 Vector: AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Full note on SAP: SAP Support Launchpad note 2417020
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
