SAP security note 2601676, "Cross-Site Scripting (XSS) vulnerability in SAP CRM WebClient UI", is a program error note released on January 8, 2019. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
SAP CRM WebClient UI does not sufficiently encode user-controlled inputs, resulting in a DOM-based Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to:
Deface or modify displayed website content
Steal user authentication information such as session data
Impersonate users to access information with their privileges
Solution
Apply the solution provided in this note or install the equivalent Support Package. Support Packages can be downloaded here.
Reason and prerequisites
The CRM WebClient UI fails to validate or encode certain URL and input fields. An attacker must trick an authenticated user into visiting a maliciously crafted website to exploit this vulnerability.
CVSS
Score 6.1 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Affected components
- WEBCUIF versions 700, 701, 730, 731, 746, 747, 748, 800, 801
Full note on SAP: SAP Support Launchpad note 2601676
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




