Medium priority
SAP security note 2872752, “[CVE-2020-6213] Cross-Site Scripting (XSS) Vulnerability in SAP NetWeaver AS ABAP (Business Server Pages Test Application SBSPEXT_PHTMLB)”, was released on April 14, 2020. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
SAP NetWeaver AS ABAP – Business Server Pages Test Application IT05 SBSPEXT_PHTMLB does not sufficiently encode user-controlled inputs, resulting in a Reflected Cross-Site Scripting (XSS) vulnerability.
Impacts of XSS Vulnerability:
- Deface or Modify Content: Non-permanently alter displayed content on a website.
- Steal Authentication Information: Extract user authentication details, such as session data.
- Impersonate Users: Access information and perform actions with the same privileges as the target user.
Solution
The BSP application now properly encodes attributes to prevent XSS attacks. Apply the relevant Support Package listed below to mitigate this vulnerability.
CVSS
Score 6.1 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
References
- CVE-2020-6213
Affected components
- SAP_BASIS (700 to 754)
Full note on SAP: SAP Support Launchpad note 2872752
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
