Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2019-0254 Cross-Site Scripting (XSS) vulnerability in SAP Disclosure Management, SAP security note 2706798

SAP Note 2706798
SAP Security Note
Medium priority

SAP security note 2706798, "[CVE-2019-0254] Cross-Site Scripting (XSS) vulnerability in SAP Disclosure Management", is a program error note released on 12.02.2019. Below are the symptom and SAP recommended solution.

ComponentEnterprise Performance Management > SAP Disclosure Management (DM) > DM core functionalities
CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
Version5
StatusReleased for Customer
Released on12.02.2019
LanguageEnglish

Description

Symptom

SAP Disclosure Management does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability.

Some well-known impacts of XSS vulnerabilities include:

  • Non-permanently deface or modify displayed content from a website
  • Steal authentication information of the user, such as data relating to their current session
  • Impersonate the user and access all information with the same rights as the target user

Solution

Manually install the SAP Disclosure Management 10.1 Application Server Stack 1301 (or a later patch version) to fix the vulnerability.

Reason and prerequisites

You are using SAP Disclosure Management 10.x up to 10.1 Stack 1300 (including).

CVSS

Score 6.5 Vector: CVSS:/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L

References

Full note on SAP: SAP Support Launchpad note 2706798

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More