SAP security note 2817937, "CVE-2019-0382: XSS Vulnerability in SAP Business Objects BI Platform (Web Intelligence)". Below are the symptom and SAP recommended solution.
Description
Symptom
SAP has released Security Note 2817937 addressing a Cross-Site Scripting (XSS) vulnerability in the SAP Business Objects BI Platform (Web Intelligence). This vulnerability arises because Web Intelligence does not sufficiently encode user-controlled inputs, potentially allowing attackers to execute malicious scripts.
Impacts of the XSS Vulnerability:
- Content Defacement: Modify or deface displayed content on a website temporarily.
- Authentication Theft: Steal user authentication details, including session data.
- User Impersonation: Gain access to information and functionalities with the same privileges as the affected user.
Solution
SAP has implemented improved encoding mechanisms to prevent the execution of injected scripts. To mitigate this vulnerability, apply the relevant support packages listed below.
Reason and prerequisites
The vulnerability exists in the BI Launchpad, where certain workflows fail to properly intercept injected scripts within requests, allowing malicious scripts to be executed.
CVSS
Score 5.4 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
References
Full note on SAP: SAP Support Launchpad note 2817937
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
