Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2018-2435 Cross-site Scripting (XSS) in SAP NetWeaver Enterprise Portal, SAP security note 2643126

SAP Note 2643126

SAP security note 2643126, "[CVE-2018-2435] Cross-site Scripting (XSS) in SAP NetWeaver Enterprise Portal". Below are the symptom and SAP recommended solution.

Description

Symptom

SAP NetWeaver Enterprise Portal does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability. This vulnerability can lead to:

  • Non-permanent defacement or modification of displayed content on a website
  • Theft of user authentication information, including session data
  • Impersonation of users with the same access rights

Solution

User-controlled inputs are now properly encoded to prevent successful XSS attacks. To address this vulnerability, apply the relevant support package patches as detailed in the note.

CVSS

Score 6.1 Vector: AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Full note on SAP: SAP Support Launchpad note 2643126

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More