Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Cross-Site Scripting (XSS) vulnerability in Text Editors for SAP CRM WebClient UI, SAP security note 2602928

SAP Note 2602928

SAP security note 2602928, "Cross-Site Scripting (XSS) Vulnerability in SAP CRM WebClient UI Text Editors", is a note. Below are the symptom and SAP recommended solution.

Description

Symptom

SAP CRM WebClient UI does not sufficiently validate and/or encode hidden fields, resulting in a DOM-based Cross-Site Scripting (XSS) vulnerability.

Impacts of XSS Vulnerability:

Non-permanent defacement or modification of displayed content on a website.

Theft of user authentication information, such as data related to the current session.

Impersonation of the user to access all information with the same rights as the target user.

Solution

Implement the solution provided in SAP Note 2602928, or install the equivalent Support Package.

For more details, refer to the SAP Note 2602928.

Reason and prerequisites

Text editors for CRM WebClient UI do not validate/encode some hidden fields. An attacker needs to trick an already authenticated user into visiting a prepared website to launch the attack.

CVSS

Score 6.1 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Full note on SAP: SAP Support Launchpad note 2602928

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More