SAP security note 2773086, "[CVE-2019-0298] Cross-Site Scripting (XSS) Vulnerability in SAP E-Commerce (Business-to-Consumer) Application", was released on May 14, 2019. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A Cross-Site Scripting (XSS) vulnerability exists in the SAP E-Commerce (Business-to-Consumer) application due to insufficient encoding of user-controlled inputs. This vulnerability allows attackers to:
- Deface or modify displayed content on a website temporarily.
- Steal user authentication information, including session data.
- Impersonate users and access information with the same privileges as the targeted user.
Solution
To mitigate this vulnerability, apply the Support Package (SP) Patch Level attached to this note. The patch addresses the insufficient output encoding issue. For detailed instructions on installing Java patches, refer to SAP Note 877887. Information about the patch strategy can be found in SAP Note 1546959.
CVSS
Score 6.1 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
References
- SAP Note 877887 – Installing Patches for CRM Java Components and FSCM BD
- SAP Note 1546959 – Patch strategies for SAP E-Commerce solutions
Affected components
- SAP-CRMJAV
- SAP-CRMWEB
- SAP-SHRWEB
- SAP-SHRJAV
- SAP-CRMAPP
- SAP-SHRAPP
Full note on SAP: SAP Support Launchpad note 2773086
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
