Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2018-2486 Cross-Site Scripting (XSS) vulnerability in SAP Marketing Content Studio, SAP security note 2705204

SAP Note 2705204
Medium priority

SAP security note 2705204, "[CVE-2018-2486] Cross-Site Scripting (XSS) vulnerability in SAP Marketing Content Studio", is a program error note released on December 11, 2018. Below are the symptom and SAP recommended solution.

CategoryProgram error
PriorityCorrection with medium priority
StatusReleased for Customer
Released onDecember 11, 2018

Description

Symptom

SAP Marketing Content Studio does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability.

  • Non-permanently deface or modify displayed content from a website.
  • Steal authentication information of the user, such as data relating to their current session.
  • Impersonate the user and access all information with the same rights as the target user.

Solution

Extended validation of input has been added. Please upgrade to a newer version of SAP Note for "Correction for Message Editor" corresponding to your Product Version/Release. Refer to the References section below for more details.

Reason and prerequisites

The input validation was not sufficient in the SAP Marketing Content Studio. Only authenticated and authorized users can exploit this vulnerability.

CVSS

Score 5.4 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

References

Full note on SAP: SAP Support Launchpad note 2705204

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More