Medium priority
SAP security note 2705204, "[CVE-2018-2486] Cross-Site Scripting (XSS) vulnerability in SAP Marketing Content Studio", is a program error note released on December 11, 2018. Below are the symptom and SAP recommended solution.
Description
Symptom
SAP Marketing Content Studio does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability.
- Non-permanently deface or modify displayed content from a website.
- Steal authentication information of the user, such as data relating to their current session.
- Impersonate the user and access all information with the same rights as the target user.
Solution
Extended validation of input has been added. Please upgrade to a newer version of SAP Note for "Correction for Message Editor" corresponding to your Product Version/Release. Refer to the References section below for more details.
Reason and prerequisites
The input validation was not sufficient in the SAP Marketing Content Studio. Only authenticated and authorized users can exploit this vulnerability.
CVSS
Score 5.4 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
References
- 2663513 – Corrections for Message Editor 1808 SP0
- 2581639 – Corrections for Message Editor release 1802/1709 SP01
- 2498239 – Corrections for Message Editor SP7 1708 / 1709
- 2404008 – Corrections for Message Editor SP5 1702
- 2386667 – Corrections for Message Editor SP4 1611
Full note on SAP: SAP Support Launchpad note 2705204
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
