Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Cross-Site Scripting (XSS) vulnerability in SAP CRM WebClient UI, SAP security note 2601676

SAP Note 2601676SAP Security NoteMedium priority

SAP security note 2601676, "Cross-Site Scripting (XSS) vulnerability in SAP CRM WebClient UI", is a program error note released on January 8, 2019. Below are the symptom, SAP recommended solution and the affected software components.

ComponentCross-Application Components > WebClient User Interface > User Interface
CategoryProgram error
PriorityMedium priority
TypeSAP Security Note
Version3
StatusReleased for Customer
Released onJanuary 8, 2019
LanguageEnglish

Description

Symptom

SAP CRM WebClient UI does not sufficiently encode user-controlled inputs, resulting in a DOM-based Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to:

Deface or modify displayed website content

Steal user authentication information such as session data

Impersonate users to access information with their privileges

Solution

Apply the solution provided in this note or install the equivalent Support Package. Support Packages can be downloaded here.

Reason and prerequisites

The CRM WebClient UI fails to validate or encode certain URL and input fields. An attacker must trick an authenticated user into visiting a maliciously crafted website to exploit this vulnerability.

CVSS

Score 6.1 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected components

  • WEBCUIF versions 700, 701, 730, 731, 746, 747, 748, 800, 801

Full note on SAP: SAP Support Launchpad note 2601676

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More