Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2018-2364 Cross-Site Scripting (XSS) vulnerability in SAP CRM WebClient UI, SAP security note 2541700

SAP Note 2541700

SAP security note 2541700, "[CVE-2018-2364] Cross-Site Scripting (XSS) vulnerability in SAP CRM WebClient UI", is a note released on 12.02.2018. Below are the symptom, CVSS score, SAP recommended solution and the affected software components.

ComponentCA-WUI-UI
StatusReleased for Customer
Released on12.02.2018

Description

Symptom

SAP CRM WebClient UI does not sufficiently validate and/or encode hidden fields, resulting in a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to:

  • Deface or modify displayed content on a website
  • Steal user authentication information, such as session data
  • Impersonate users and access information with the same rights as the target user

CVSS

Score 6.1/10 Vector: AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Solution

To address this vulnerability, implement the solution provided in SAP Note 2541700 or install the corresponding Support Packages.

References

  • CVE-2018-2364

Affected components

  • S4FND 102
  • WEBCUIF 701, 731, 746, 747, 748, 800, 801

Full note on SAP: SAP Support Launchpad note 2541700

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More