Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Cross-Site Scripting (XSS) vulnerability in KM Portal Favorites, SAP security note 2326291

SAP Note 2326291

SAP security note 2326291, "Cross-Site Scripting (XSS) vulnerability in KM Portal Favorites". Below are the symptom and SAP recommended solution.

Description

Symptom

The KM Portal Favorites feature does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability.

Impacts of this vulnerability include:

  • Non-permanently defacing or modifying displayed content from a website
  • Stealing user authentication information, such as data related to their current session
  • Impersonating the user and accessing information with the same rights as the target user

Solution

Implement the Support Packages and Patches referenced by this SAP Note.

CVSS

Score 6.1

References

Full note on SAP: SAP Support Launchpad note 2326291

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More