SAP security note 2523913, "[CVE-2017-16681] Cross-Site Scripting (XSS) vulnerability in BI Promotion Management Application". Below are the symptom and SAP recommended solution.
Description
Symptom
The Promotion Management Application does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability. This vulnerability can allow attackers to:
- Non-permanently deface or modify displayed content from a website
- Steal authentication information of the user, such as session data
- Impersonate the user and access all information with the same rights as the target user
Solution
The URL parameters have been properly encoded to prevent successful XSS attacks. This issue is or will be fixed in the patches listed in the "Support Packages & Patches" section below. For more information on the Business Intelligence Platform maintenance schedule and strategy, refer to SAP Note 2144559.
CVSS
Score 6.1 / 10 Vector: AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
References
Full note on SAP: SAP Support Launchpad note 2523913
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
