Medium priority
SAP security note 2372204, "Cross-Site Scripting (XSS) vulnerability in SAP Enterprise Portal Theme Editor", is a program error note released on 10.01.2017. Below are the symptom and SAP recommended solution.
Description
Symptom
Styles Integrity Test Component does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability.
Impacts of XSS Vulnerability:
- Non-permanently deface or modify displayed content from a website.
- Steal authentication information of the user, such as data relating to their current session.
- Impersonate the user and access all information with the same rights as the target user.
Solution
Output encoding functions have been implemented to address the vulnerability.
CVSS
Score 6.1 Vector: AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
References
Referenced by
- SAP Note 2463662 – Central Note for NetWeaver 7.31 SP20 Enterprise Portal Core
- SAP Note 2463570 – Collective Note: SAP NetWeaver 7.31 SP20 – Composition Platform
- SAP Note 2407374 – Central Note: SAP NetWeaver 7.5 SP07- EP Core (Application Platform)
- SAP Note 2407350 – Collective Note: SAP NetWeaver 7.5 SP07 – Composition Platform
- SAP Note 2403195 – Corrections for unified rendering 701/19 III (UR Mimes)
Full note on SAP: SAP Support Launchpad note 2372204
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
