SAP security note 2602928, "Cross-Site Scripting (XSS) Vulnerability in SAP CRM WebClient UI Text Editors", is a note. Below are the symptom and SAP recommended solution.
Description
Symptom
SAP CRM WebClient UI does not sufficiently validate and/or encode hidden fields, resulting in a DOM-based Cross-Site Scripting (XSS) vulnerability.
Impacts of XSS Vulnerability:
Non-permanent defacement or modification of displayed content on a website.
Theft of user authentication information, such as data related to the current session.
Impersonation of the user to access all information with the same rights as the target user.
Solution
Implement the solution provided in SAP Note 2602928, or install the equivalent Support Package.
For more details, refer to the SAP Note 2602928.
Reason and prerequisites
Text editors for CRM WebClient UI do not validate/encode some hidden fields. An attacker needs to trick an already authenticated user into visiting a prepared website to launch the attack.
CVSS
Score 6.1 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Full note on SAP: SAP Support Launchpad note 2602928
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



