Medium priority
SAP security note 2303032, "Cross-Site Scripting (XSS) vulnerability in CL_WDR_CLIENT_SSR_LS", is a note released on July 12, 2016. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
CL_WDR_CLIENT_SSR_LS does not sufficiently check the option to turn off external styleheets (CSS), resulting in a Cross-Site Scripting (XSS) vulnerability.
Some well-known impacts of XSS vulnerability include:
- Non-permanently defacing or modifying displayed content from a website
- Stealing authentication information of the user, such as data relating to their current session
- Impersonating the user and accessing all information with the same rights as the target user
Solution
- The option to turn off external stylesheets is now used properly.
- Implement the corresponding support packages and patches referenced by this SAP Note.
Reason and prerequisites
Program error.
Affected components
- Basis Components > Web Dynpro > Web Dynpro ABAP (BC-WD-ABA)
- SAP_UI 750
Full note on SAP: SAP Support Launchpad note 2303032
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



