SAP security note 2541700, "[CVE-2018-2364] Cross-Site Scripting (XSS) vulnerability in SAP CRM WebClient UI", is a note released on 12.02.2018. Below are the symptom, CVSS score, SAP recommended solution and the affected software components.
Description
Symptom
SAP CRM WebClient UI does not sufficiently validate and/or encode hidden fields, resulting in a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to:
- Deface or modify displayed content on a website
- Steal user authentication information, such as session data
- Impersonate users and access information with the same rights as the target user
CVSS
Score 6.1/10 Vector: AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Solution
To address this vulnerability, implement the solution provided in SAP Note 2541700 or install the corresponding Support Packages.
References
- CVE-2018-2364
Affected components
- S4FND 102
- WEBCUIF 701, 731, 746, 747, 748, 800, 801
Full note on SAP: SAP Support Launchpad note 2541700
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
