Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Cross-Site Scripting (XSS) vulnerability in CRM Interaction Center, SAP security note 2606194

SAP Note 2606194

SAP security note 2606194, "Cross-Site Scripting (XSS) vulnerability in CRM Interaction Center". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

The CRM Interaction Center does not sufficiently encode user-controlled inputs, resulting in an XSS vulnerability. Potential impacts include:

  • Defacing or modifying website content temporarily.
  • Stealing user authentication information, such as session data.
  • Impersonating users and accessing information with their privileges.

Solution

To mitigate this vulnerability:

Reason and prerequisites

This issue occurs when a user enters vulnerable data in the account field while creating a new business partner.

CVSS

Score 4.4 Vector: CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N

Affected components

  • S4CRM 100
  • BBPCRM 600, 700, 701, 702, 712, 713, 714

Full note on SAP: SAP Support Launchpad note 2606194

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More