Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2017-16681 Cross-Site Scripting (XSS) vulnerability in BI Promotion Management Application, SAP security note 2523913

SAP Note 2523913

SAP security note 2523913, "[CVE-2017-16681] Cross-Site Scripting (XSS) vulnerability in BI Promotion Management Application". Below are the symptom and SAP recommended solution.

Description

Symptom

The Promotion Management Application does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability. This vulnerability can allow attackers to:

  • Non-permanently deface or modify displayed content from a website
  • Steal authentication information of the user, such as session data
  • Impersonate the user and access all information with the same rights as the target user

Solution

The URL parameters have been properly encoded to prevent successful XSS attacks. This issue is or will be fixed in the patches listed in the "Support Packages & Patches" section below. For more information on the Business Intelligence Platform maintenance schedule and strategy, refer to SAP Note 2144559.

CVSS

Score 6.1 / 10 Vector: AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

References

Full note on SAP: SAP Support Launchpad note 2523913

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More