Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2019-0368 Cross-Site Scripting (XSS) vulnerability in Customer relationship management (Email management), SAP security note 2751806

SAP Note 2751806
SAP Security Note
Medium priority

SAP security note 2751806, "[CVE-2019-0368] Cross-Site Scripting (XSS) vulnerability in CRM Email Management", is a program error note released on 08.10.2019. Below are the symptom and SAP recommended solution.

ComponentCustomer Relationship Management > Basic Functions > Email Management (CRM-BF-ML)
CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
Version9
StatusReleased for Customer
Released on08.10.2019
LanguageEnglish

Description

Symptom

Customer Relationship Management does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to:

  • Impersonate the user and access all information with the same rights as the target user.
  • Inject scripts via input parameters to extract system information and data stored on the server.

Solution

To resolve this issue, user-controlled inputs are now encoded. Implement the following SAP Security Note to mitigate the vulnerability.

Reason and prerequisites

Reason: Certain parameters are not properly encoded, leading to the vulnerability. Pre-requisites: Email integration functionality must be enabled in CRM.

CVSS

Score 5.4 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Full note on SAP: SAP Support Launchpad note 2751806

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More