Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Cross-Site Scripting (XSS) vulnerability in CL_WDR_CLIENT_SSR_LS, SAP security note 2303032

SAP Note 2303032
Medium priority

SAP security note 2303032, "Cross-Site Scripting (XSS) vulnerability in CL_WDR_CLIENT_SSR_LS", is a note released on July 12, 2016. Below are the symptom, SAP recommended solution and the affected software components.

PriorityMedium priority
StatusReleased for Customer
Released onJuly 12, 2016

Description

Symptom

CL_WDR_CLIENT_SSR_LS does not sufficiently check the option to turn off external styleheets (CSS), resulting in a Cross-Site Scripting (XSS) vulnerability.

Some well-known impacts of XSS vulnerability include:

  • Non-permanently defacing or modifying displayed content from a website
  • Stealing authentication information of the user, such as data relating to their current session
  • Impersonating the user and accessing all information with the same rights as the target user

Solution

  • The option to turn off external stylesheets is now used properly.
  • Implement the corresponding support packages and patches referenced by this SAP Note.

Reason and prerequisites

Program error.

Affected components

  • Basis Components > Web Dynpro > Web Dynpro ABAP (BC-WD-ABA)
  • SAP_UI 750

Full note on SAP: SAP Support Launchpad note 2303032

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More