SAP security note 2878935, “[CVE-2020-6246] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS ABAP (Business Server Pages Test Application SBSPEXT_TABLE)”, is a note released on June 9, 2020. Below are the symptom and SAP recommended solution.
Description
Symptom
A Cross-Site Scripting (XSS) vulnerability has been identified in the SAP NetWeaver AS ABAP – Business Server Pages Test Application SBSPEXT_TABLE. The application fails to sufficiently encode user-controlled inputs, which allows attackers to execute arbitrary scripts in the context of a user’s browser session.
Solution
SAP has provided patches that properly encode URL parameters to prevent XSS attacks. Administrators should ensure the SICF node /sap/bc/bsp/sap/sbspext_table is secured or disabled if not in use.
CVSS
Score 6.1
References
- CVE-2020-6246
Full note on SAP: SAP Support Launchpad note 2878935
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
