Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Cross-Site Scripting (XSS) vulnerability in ITS / SAP GUI for HTML, SAP security note 2350276

SAP Note 2350276

SAP security note 2350276, "Cross-Site Scripting (XSS) vulnerability in ITS / SAP GUI for HTML". Below are the symptom and SAP recommended solution.

Description

Symptom

ITS/SAP GUI for HTML does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability.

Impacts of XSS Vulnerability:

  • Non-permanently deface or modify displayed content from a website
  • Steal authentication information of the user, such as data relating to their current session
  • Impersonate the user and access all information with the same rights as the target user

Solution

Please install the Basis Support Package related to this SAP Note. Additionally, a correction instruction is attached and can be implemented via SNOTE.

Reason and prerequisites

Integrated ITS / ABAP Handler CL_HTTP_EXT_ITS

CVSS

Score 0

Full note on SAP: SAP Support Launchpad note 2350276

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More