Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Cross-Site Scripting (XSS) vulnerability in SAP CRM WebClient UI, SAP security note 2923035

SAP Note 2923035
SAP Security Note
Medium priority

SAP security note 2923035, "Cross-Site Scripting (XSS) vulnerability in SAP CRM WebClient UI", is released on June 9, 2020. Below are the symptom, SAP recommended solution and the affected software components.

PriorityCorrection with medium priority
TypeSAP Security Note
StatusReleased for Customer
Released onJune 9, 2020

Description

Symptom

A Cross-Site Scripting (XSS) vulnerability has been identified in SAP CRM WebClient UI due to insufficient encoding of user-controlled inputs. This vulnerability can allow attackers to:

  • Deface or modify website content
  • Steal user authentication information
  • Impersonate users and access information with their privileges

If exploited, this vulnerability could lead to unauthorized access to sensitive information and manipulation of web content, potentially compromising the integrity and confidentiality of user data.

Solution

  • URL Parameter Encoding: URL parameters are now properly encoded to prevent XSS attacks.
  • Apply Support Packages and Patches: implement the Support Packages and Patches referenced in this SAP Note.

CVSS

Score 4.4 Vector: CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N

References

Affected components

  • S4FND: Versions 102, 103, 104
  • WEBCUIF: Versions 731, 746, 747, 748, 800, 801

Full note on SAP: SAP Support Launchpad note 2923035

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More