Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Cross-Site Scripting (XSS) vulnerability in SAP GUI HTML Control, SAP security note 2383017

SAP Note 2383017SAP Security NoteMedium priority

SAP security note 2383017, "Cross-Site Scripting (XSS) vulnerability in SAP GUI HTML Control", is a program error note released on September 11, 2018. Below are the symptom and SAP recommended solution.

ComponentBasis Components > Frontend Services (SAP Note 1322184) > SAP GUI for Windows Controls
CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
Version5
StatusReleased for Customer
Released onSeptember 11, 2018
LanguageEnglish

Description

Symptom

SAP applications that display and process HTML documents can be abused by an attacker, allowing them to modify application content, persist the modified content without authorization, and potentially obtain authentication information from other legitimate users.

Solution

The filter functionality used by SAP applications that display and process HTML documents has been corrected and improved with a correction described in this note. To solve the issue, you need to install the support package or implement the correction instructions listed in this note.

CVSS

Score 5.4 / 10 Vector: AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

References

Full note on SAP: SAP Support Launchpad note 2383017

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More