SAP security note 2618337, "[CVE-2018-2466] Cross-Site Scripting (XSS) vulnerability in SAP Data Services Management Console". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Impact and Lineage Analysis in SAP Data Services Management Console does not sufficiently validate user controlled inputs, which results in Cross-Site Scripting (XSS) vulnerability.
Solution
The validation of input is added now, please upgrade to a newer version. This correction is delivered in the release(s) listed in the Support Packages and Patches section of this SAP Note.
Reason and prerequisites
The input validation was missing in the Impact and Lineage Analysis.
CVSS
Score 5.4 / 10 Vector: AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Affected components
- SAP Data Services 4.2
Full note on SAP: SAP Support Launchpad note 2618337
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
