SAP security note 2425744, "XSS Vulnerability in SAP CRM WebClient UI". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
The SAP CRM WebClient UI does not sufficiently encode user-controlled inputs, resulting in an XSS vulnerability. Attackers can exploit this by tricking authenticated users into visiting a maliciously crafted website, enabling the execution of arbitrary scripts within the context of the user’s session.
Exploitation of this XSS vulnerability can lead to:
- Defacement or modification of displayed web content.
- Theft of user authentication information, including session data.
- Impersonation of the user, granting access with the same privileges.
- Unauthorized execution of commands.
Solution
To mitigate this vulnerability, SAP recommends implementing the provided solution or installing the equivalent Support Package.
This issue is externally reported and has a medium priority correction. No known side effects are associated with applying this security note. However, note that SAP Note 2629592 addresses the wrong escaping of custom error messages, which may be related.
CVSS
Score 6.1
References
Affected components
- WEBCUIF 701
- WEBCUIF 731
- WEBCUIF 746
- WEBCUIF 747
- WEBCUIF 748
- WEBCUIF 800
- WEBCUIF 801
Full note on SAP: SAP Support Launchpad note 2425744
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
