Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2020-6213Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS ABAP(Business Server Pages Test Application SBSPEXT_PHTMLB), SAP security note 2872752

SAP Note 2872752
Medium priority

SAP security note 2872752, “[CVE-2020-6213] Cross-Site Scripting (XSS) Vulnerability in SAP NetWeaver AS ABAP (Business Server Pages Test Application SBSPEXT_PHTMLB)”, was released on April 14, 2020. Below are the symptom, SAP recommended solution and the affected software components.

ComponentBasis Components > Business Server Pages
PriorityMedium priority
StatusReleased for Customer
Released onApril 14, 2020

Description

Symptom

SAP NetWeaver AS ABAP – Business Server Pages Test Application IT05 SBSPEXT_PHTMLB does not sufficiently encode user-controlled inputs, resulting in a Reflected Cross-Site Scripting (XSS) vulnerability.

Impacts of XSS Vulnerability:

  • Deface or Modify Content: Non-permanently alter displayed content on a website.
  • Steal Authentication Information: Extract user authentication details, such as session data.
  • Impersonate Users: Access information and perform actions with the same privileges as the target user.

Solution

The BSP application now properly encodes attributes to prevent XSS attacks. Apply the relevant Support Package listed below to mitigate this vulnerability.

CVSS

Score 6.1 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

References

  • CVE-2020-6213

Affected components

  • SAP_BASIS (700 to 754)

Full note on SAP: SAP Support Launchpad note 2872752

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More