Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2018-2434 Content Spoofing vulnerability in SAP_UI component, SAP security note 2633180

SAP Note 2633180
SAP Security Note
Medium priority

SAP security note 2633180, "[CVE-2018-2434] Content Spoofing vulnerability in SAP_UI component", is a program error note released on 10.08.2018. Below are the symptom, SAP recommended solution and the affected software components.

ComponentCross-Application Components > SAPUI5 > ABAP (see SAP Note 2549631) > UI5 App Infrastructure: SAPUI5 ABAP Repository
CategoryProgram error
PriorityMedium priority
TypeSAP Security Note
Version8
StatusReleased for Customer
Released on10.08.2018
LanguageEnglish

Description

Symptom

UPDATE 10th August 2018: This note has been re-released with updated "Validity" and "Support Packages & Patches" information.

A content spoofing vulnerability allows an attacker to render HTML pages containing arbitrary plain text content, which might trick an end user.

Note: It is not possible to embed active content like JavaScript or hyperlinks.

Solution

Implement this note to consume the solution. There’s no negative impact on standard behavior.

CVSS

Score 4.3 Vector: AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Affected components

  • UI_INFRA 100 to 100
  • SAP_UI 740 to 740
  • SAP_UI 750 to 750
  • SAP_UI 751 to 751
  • SAP_UI 752 to 752
  • UI_700 200 to 200

Full note on SAP: SAP Support Launchpad note 2633180

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More