Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2019-0311 Cross Site Scripting (XSS) vulnerability in Automotive Dealer Portal of SAP R/3 Enterprise Application, SAP security note 2728153

SAP Note 2728153

SAP security note 2728153, "[CVE-2019-0311] Cross Site Scripting (XSS) vulnerability in Automotive Dealer Portal of SAP R/3 Enterprise Application". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

The BSP-based Automotive Dealer Portal application in SAP R/3 does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability.

  • Non-permanently defacing or modifying displayed content from a website
  • Stealing authentication information of the user, such as data relating to their current session
  • Impersonating the user and accessing all information with the same rights as the target user

Solution

This issue is fixed in the patches listed in the "Support Packages & Patches" section below. The relevant patch levels will be released and populated accordingly.

CVSS

Score 6.1 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

References

  • SAP Support Note 2728153

Affected components

  • Industry-Specific Components > Automotive > Dealer Portal > Spare Parts Online WebFrontend (IS-A-DP-SPP)

Full note on SAP: SAP Support Launchpad note 2728153

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More