Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Cross-Site Scripting (XSS) vulnerability in Infoview – Titan, SAP security note 2250817

SAP Note 2250817
SAP Security Note
Medium priority

SAP security note 2250817, “Cross-Site Scripting (XSS) Vulnerability in Infoview – Titan”, is a program error note released on 08.02.2017. Below are the symptom, SAP recommended solution and the affected software components.

ComponentBusiness Intelligence Solutions > Business Intelligence Platform > InfoView, BI Launch Pad
CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
Version7
StatusReleased for Customer
Released on08.02.2017

Description

Symptom

Titan Infoview does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability. This vulnerability can allow attackers to deface or modify website content, steal user authentication information, or impersonate users with the same access rights.

Solution

The issue is resolved in the following Support Package Patches for BOBJ ENTERPRISE XI 3.1:

  • SP007 Patch 000004
  • SP006 Patch 000007

Ensure to apply the appropriate patches promptly to mitigate the vulnerability.

CVSS

Score 6.1 Vector: AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

References

Affected components

  • ENTERPRISE XI 3.0
  • ENTERPRISE XI 3.1
  • ENTERPRISE XI 3.0a

Full note on SAP: SAP Support Launchpad note 2250817

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More