Medium priority
SAP security note 2473504, “Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Analysis Edition for OLAP”, is a program error note released on November 14, 2017. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Analysis Edition for OLAP does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to:
- Deface or modify website content temporarily.
- Steal user authentication information, including session data.
- Impersonate users and access information with the same privileges.
Solution
The issue has been addressed by removing the problematic JSP resource, which is unnecessary for BI Applications.
CVSS
Score 6.1 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
References
Affected components
- ENTERPRISE 410, 420, 430
Full note on SAP: SAP Support Launchpad note 2473504
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
