SAP security note 2606194, "Cross-Site Scripting (XSS) vulnerability in CRM Interaction Center". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
The CRM Interaction Center does not sufficiently encode user-controlled inputs, resulting in an XSS vulnerability. Potential impacts include:
- Defacing or modifying website content temporarily.
- Stealing user authentication information, such as session data.
- Impersonating users and accessing information with their privileges.
Solution
To mitigate this vulnerability:
- Apply the Correction Instructions provided in the note.
- Implement the Support Packages and Patches referenced by this SAP Note.
- Ensure that SAP Note 1582870 – ABAP XSS Escaping Support is imported as a prerequisite.
Reason and prerequisites
This issue occurs when a user enters vulnerable data in the account field while creating a new business partner.
CVSS
Score 4.4 Vector: CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N
Affected components
- S4CRM 100
- BBPCRM 600, 700, 701, 702, 712, 713, 714
Full note on SAP: SAP Support Launchpad note 2606194
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
