Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2019-0298 Cross-Site Scripting (XSS) vulnerability in SAP E-Commerce (Business-to-Consumer) application, SAP security note 2773086

SAP Note 2773086Medium priority

SAP security note 2773086, "[CVE-2019-0298] Cross-Site Scripting (XSS) Vulnerability in SAP E-Commerce (Business-to-Consumer) Application", was released on May 14, 2019. Below are the symptom, SAP recommended solution and the affected software components.

ComponentCustomer Relationship Management > Internet Sales > Shopping Basket and Order Entry
PriorityMedium priority
StatusReleased for Customer
Released onMay 14, 2019

Description

Symptom

A Cross-Site Scripting (XSS) vulnerability exists in the SAP E-Commerce (Business-to-Consumer) application due to insufficient encoding of user-controlled inputs. This vulnerability allows attackers to:

  • Deface or modify displayed content on a website temporarily.
  • Steal user authentication information, including session data.
  • Impersonate users and access information with the same privileges as the targeted user.

Solution

To mitigate this vulnerability, apply the Support Package (SP) Patch Level attached to this note. The patch addresses the insufficient output encoding issue. For detailed instructions on installing Java patches, refer to SAP Note 877887. Information about the patch strategy can be found in SAP Note 1546959.

CVSS

Score 6.1 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

References

Affected components

  • SAP-CRMJAV
  • SAP-CRMWEB
  • SAP-SHRWEB
  • SAP-SHRJAV
  • SAP-CRMAPP
  • SAP-SHRAPP

Full note on SAP: SAP Support Launchpad note 2773086

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More