Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Cross-Site Scripting (XSS) vulnerability in PI Message Display Tool, SAP security note 2344441

SAP Note 2344441

SAP security note 2344441, “Cross-Site Scripting (XSS) vulnerability in PI Message Display Tool.” Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

A Cross-Site Scripting (XSS) vulnerability has been identified in the PI Message Display Tool. This vulnerability arises because the tool does not sufficiently encode user-controlled inputs, allowing malicious scripts to be executed in the context of the user’s browser.

The PI Message Display Tool fails to properly encode user inputs, resulting in the possibility of XSS attacks. This can lead to:

  • Non-permanent defacement or modification of displayed content on a website.
  • Theft of authentication information, such as session data.
  • Impersonation of the user, granting access to information with the same privileges as the target user.

Solution

This vulnerability has been addressed in the Support Packages and Patches referenced by this SAP Security Note. It is recommended to apply the relevant patches to mitigate the risk.

CVSS

Score 6.1/10 Vector: AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected components

  • MESSAGING SYSTEM SERVICE: Versions 7.10 to 7.50
  • SAP_XIAF: Versions 7.00 to 7.02

Full note on SAP: SAP Support Launchpad note 2344441

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More