Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Cross-Site Scripting (XSS) vulnerability in SAP CRM WebClient UI, SAP security note 2425744

SAP Note 2425744

SAP security note 2425744, "XSS Vulnerability in SAP CRM WebClient UI". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

The SAP CRM WebClient UI does not sufficiently encode user-controlled inputs, resulting in an XSS vulnerability. Attackers can exploit this by tricking authenticated users into visiting a maliciously crafted website, enabling the execution of arbitrary scripts within the context of the user’s session.

Exploitation of this XSS vulnerability can lead to:

  • Defacement or modification of displayed web content.
  • Theft of user authentication information, including session data.
  • Impersonation of the user, granting access with the same privileges.
  • Unauthorized execution of commands.

Solution

To mitigate this vulnerability, SAP recommends implementing the provided solution or installing the equivalent Support Package.

This issue is externally reported and has a medium priority correction. No known side effects are associated with applying this security note. However, note that SAP Note 2629592 addresses the wrong escaping of custom error messages, which may be related.

CVSS

Score 6.1

References

Affected components

  • WEBCUIF 701
  • WEBCUIF 731
  • WEBCUIF 746
  • WEBCUIF 747
  • WEBCUIF 748
  • WEBCUIF 800
  • WEBCUIF 801

Full note on SAP: SAP Support Launchpad note 2425744

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More