Medium priority
SAP security note 2481262, "Cross-Site Scripting (XSS) vulnerability in SAP CRM IPC Pricing", is a program error note released on August 8, 2017. Below are the symptom and SAP recommended solution.
Description
Symptom
IPC Pricing does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability.
Impacts of XSS Vulnerability:
- Non-permanently deface or modify displayed content from a website.
- Steal authentication information of the user, such as data relating to their current session.
- Impersonate the user and access all information with the same rights as the target user.
Solution
The code has been removed, preventing a successful XSS attack as the code is obsolete. This SAP note contains Java Corrections for E-Commerce / Web Channel. Apply the patches as mentioned in the "Support Packages & Patches" section.
For further information about installing Java Patches, consult Note 877887. Information about the patch strategy can be found in Note 1546959.
Reason and prerequisites
Reason: IPC Pricing does not sufficiently encode INPUT parameters, resulting in a reflected cross-site scripting issue.
CVSS
Score 6.1 Vector: AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
References
Referenced by
Full note on SAP: SAP Support Launchpad note 2481262
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
