Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Knowledge Management XMLForms, SAP security note 2464582

SAP Note 2464582

SAP security note 2464582, “Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Knowledge Management XMLForms”. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

SAP NetWeaver Knowledge Management XML FormBuilder/XMLForms does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability.

  • Non-permanently deface or modify displayed content from a website
  • Steal authentication information of the user, such as data relating to their current session
  • Impersonate the user and access all information with the same rights as the target user

Solution

  • The URL parameters are now properly encoded to prevent a successful XSS attack.
  • Implement the Support Packages and Patches referenced by this SAP Note.

CVSS

Score 5.4 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Affected components

  • KMC-CM 7.00 to 7.50

Full note on SAP: SAP Support Launchpad note 2464582

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More