SAP security note 2728153, "[CVE-2019-0311] Cross Site Scripting (XSS) vulnerability in Automotive Dealer Portal of SAP R/3 Enterprise Application". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
The BSP-based Automotive Dealer Portal application in SAP R/3 does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability.
- Non-permanently defacing or modifying displayed content from a website
- Stealing authentication information of the user, such as data relating to their current session
- Impersonating the user and accessing all information with the same rights as the target user
Solution
This issue is fixed in the patches listed in the "Support Packages & Patches" section below. The relevant patch levels will be released and populated accordingly.
CVSS
Score 6.1 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
References
- SAP Support Note 2728153
Affected components
- Industry-Specific Components > Automotive > Dealer Portal > Spare Parts Online WebFrontend (IS-A-DP-SPP)
Full note on SAP: SAP Support Launchpad note 2728153
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
