SAP Security Note
Medium priority
SAP security note 2923035, "Cross-Site Scripting (XSS) vulnerability in SAP CRM WebClient UI", is released on June 9, 2020. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A Cross-Site Scripting (XSS) vulnerability has been identified in SAP CRM WebClient UI due to insufficient encoding of user-controlled inputs. This vulnerability can allow attackers to:
- Deface or modify website content
- Steal user authentication information
- Impersonate users and access information with their privileges
If exploited, this vulnerability could lead to unauthorized access to sensitive information and manipulation of web content, potentially compromising the integrity and confidentiality of user data.
Solution
- URL Parameter Encoding: URL parameters are now properly encoded to prevent XSS attacks.
- Apply Support Packages and Patches: implement the Support Packages and Patches referenced in this SAP Note.
CVSS
Score 4.4 Vector: CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N
References
Affected components
- S4FND: Versions 102, 103, 104
- WEBCUIF: Versions 731, 746, 747, 748, 800, 801
Full note on SAP: SAP Support Launchpad note 2923035
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
