Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2018-2466 Cross-Site Scripting (XSS) vulnerability in SAP Data Services Management Console, SAP security note 2618337

SAP Note 2618337

SAP security note 2618337, "[CVE-2018-2466] Cross-Site Scripting (XSS) vulnerability in SAP Data Services Management Console". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

Impact and Lineage Analysis in SAP Data Services Management Console does not sufficiently validate user controlled inputs, which results in Cross-Site Scripting (XSS) vulnerability.

Solution

The validation of input is added now, please upgrade to a newer version. This correction is delivered in the release(s) listed in the Support Packages and Patches section of this SAP Note.

Reason and prerequisites

The input validation was missing in the Impact and Lineage Analysis.

CVSS

Score 5.4 / 10 Vector: AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Affected components

  • SAP Data Services 4.2

Full note on SAP: SAP Support Launchpad note 2618337

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More