SAP security note 2326291, "Cross-Site Scripting (XSS) vulnerability in KM Portal Favorites". Below are the symptom and SAP recommended solution.
Description
Symptom
The KM Portal Favorites feature does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability.
Impacts of this vulnerability include:
- Non-permanently defacing or modifying displayed content from a website
- Stealing user authentication information, such as data related to their current session
- Impersonating the user and accessing information with the same rights as the target user
Solution
Implement the Support Packages and Patches referenced by this SAP Note.
CVSS
Score 6.1
References
Referenced by
- 2332246: Collective Note: SAP NetWeaver 7.30 SP17 – Enterprise Portal
- 2332266: Collective Note: SAP NetWeaver 7.30 SP17 – Composition Platform
- 2463662: Central Note for NetWeaver 7.31 SP20 Enterprise Portal Core
- 2463671: Central Note for NetWeaver 7.31 SP20 Enterprise Portal
- 2463570: Collective Note: SAP NetWeaver 7.31 SP20 – Composition Platform
- 2407374: Central Note: SAP NetWeaver 7.5 SP07- EP Core (Application Platform)
- 2407350: Collective Note: SAP NetWeaver 7.5 SP07 – Composition Platform
- 2403329: Add to Portal Favorites via DTN in Classic Framework Page is not working
- 2419937: Portal Favorites not working in Classic Framework Page
Full note on SAP: SAP Support Launchpad note 2326291
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
