SAP security note 3102769, "CVE-2021-42063 XSS Vulnerability in SAP Knowledge Warehouse". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
UPDATE 13th June 2023: this note has been re-released with updated "Support Packages & Patches" information for releases 7.31 and 7.40.
UPDATE 23rd August 2022: this note has been re-released with updated ‘Solution’ information. The workaround information is moved to new SAP Note 3221696.
A security vulnerability has been discovered in the SAP Knowledge Warehouse (SAP KW). The usage of one SAP KW component within a web browser enables unauthorized attackers to conduct XSS attacks, which might lead to the disclosure of sensitive data.
Solution
With this correction, the parameters will be properly validated and encoded to prevent a successful XSS attack. Implement the support packages and patches referenced by this SAP Note.
Workaround: if you cannot implement the patch, you have two options for a workaround, which are described in SAP Note 3221696 "Deactivating of SAP IKS component." Please assess the workaround applicability for your SAP landscape prior to implementation. This workaround is a temporary fix and is not a permanent solution; SAP strongly recommends applying the corrections outlined in the security note, which can be done in lieu of the workaround or after the workaround is implemented.
Reason and prerequisites
The displaying component of SAP KW did not sufficiently validate and encode input parameters, resulting in a reflected cross-site scripting issue. The security breach might also occur if you do not actively use the displaying component of SAP KW; simply the existence of the component on your landscape is sufficient.
CVSS
Score 8.8 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:L
References
Affected components
- KM-KW_JIKS: 7.30, 7.31, 7.40, 7.50
Full note on SAP: SAP Support Launchpad note 3102769
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
