SAP Security Note
Medium priority
SAP security note 2633180, "[CVE-2018-2434] Content Spoofing vulnerability in SAP_UI component", is a program error note released on 10.08.2018. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
UPDATE 10th August 2018: This note has been re-released with updated "Validity" and "Support Packages & Patches" information.
A content spoofing vulnerability allows an attacker to render HTML pages containing arbitrary plain text content, which might trick an end user.
Note: It is not possible to embed active content like JavaScript or hyperlinks.
Solution
Implement this note to consume the solution. There’s no negative impact on standard behavior.
CVSS
Score 4.3 Vector: AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Affected components
- UI_INFRA 100 to 100
- SAP_UI 740 to 740
- SAP_UI 750 to 750
- SAP_UI 751 to 751
- SAP_UI 752 to 752
- UI_700 200 to 200
Full note on SAP: SAP Support Launchpad note 2633180
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



