SAP security note 2804833, "[CVE-2019-0329] Cross-Site Scripting (XSS) vulnerability in SAP Information Steward 4.2", is a note released on July 9, 2019. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A Cross-Site Scripting (XSS) vulnerability has been identified in SAP Information Steward 4.2. The application does not sufficiently encode user-controlled inputs, allowing attackers to execute malicious scripts in the context of a user’s browser session.
Impact:
- Defacement or unauthorized modification of website content.
- Theft of authentication information, including session data.
- User impersonation, granting attackers access with the same privileges as the targeted user.
Solution
SAP has addressed this vulnerability by properly encoding URL parameters to prevent successful XSS attacks. The correction is available through the relevant Support Packages and Patches.
CVSS
Score 6.1 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Affected components
- Enterprise Information Management Solutions > Information Steward (EIM-IS), version 4.2
Full note on SAP: SAP Support Launchpad note 2804833
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
