Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Cross-Site Scripting (XSS) vulnerability in ITS / SAP GUI for HTML, SAP security note 2318760

SAP Note 2318760SAP Security NoteHigh priority

SAP security note 2318760, "Cross-Site Scripting (XSS) vulnerability in ITS / SAP GUI for HTML", is a program error note released on 13.03.2017. Below are the symptom and SAP recommended solution.

ComponentBC-FES-ITS
CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
Version2
StatusReleased for Customer
Released on13.03.2017
LanguageEnglish

Description

Symptom

ITS / SAP GUI for HTML does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability.

Some well-known impacts of XSS vulnerability are:

  • Non-permanently deface or modify displayed content from a website.
  • Steal authentication information of the user, such as data relating to their current session.
  • Impersonate the user and access all information with the same rights as the target user.

Solution

Please see "Support Packaged & Patches" for released Support Packages.

Reason and prerequisites

Integrated ITS

Full note on SAP: SAP Support Launchpad note 2318760

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More