Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2019-0329 Cross-Site Scripting (XSS) vulnerability in SAP Information Steward 4.2, SAP security note 2804833

SAP Note 2804833

SAP security note 2804833, "[CVE-2019-0329] Cross-Site Scripting (XSS) vulnerability in SAP Information Steward 4.2", is a note released on July 9, 2019. Below are the symptom, SAP recommended solution and the affected software components.

ComponentEnterprise Information Management Solutions > Information Steward (EIM-IS)
Version4.2
StatusReleased for Customer
Released onJuly 9, 2019

Description

Symptom

A Cross-Site Scripting (XSS) vulnerability has been identified in SAP Information Steward 4.2. The application does not sufficiently encode user-controlled inputs, allowing attackers to execute malicious scripts in the context of a user’s browser session.

Impact:

  • Defacement or unauthorized modification of website content.
  • Theft of authentication information, including session data.
  • User impersonation, granting attackers access with the same privileges as the targeted user.

Solution

SAP has addressed this vulnerability by properly encoding URL parameters to prevent successful XSS attacks. The correction is available through the relevant Support Packages and Patches.

CVSS

Score 6.1 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected components

  • Enterprise Information Management Solutions > Information Steward (EIM-IS), version 4.2

Full note on SAP: SAP Support Launchpad note 2804833

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More