SAP Security Note
Medium priority
SAP security note 2872545, “[CVE-2020-6217] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS ABAP (Business Server Pages Test Application IT05)”, is a program error note released on 14.04.2020. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
SAP NetWeaver AS ABAP – Business Server Pages Test Application IT05 does not sufficiently encode user-controlled inputs, resulting in a Reflected Cross-Site Scripting (XSS) vulnerability.
Impacts of XSS Vulnerability:
- Non-permanently deface or modify displayed content from a website.
- Steal authentication information of the user, such as data relating to their current session.
- Impersonate the user and access all information with the same rights as the target user.
Solution
The attributes are now properly encoded to prevent a successful XSS attack.
CVSS
Score 6.1 Vector: CVSS:/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Affected components
- SAP_BASIS 700 to 702
- SAP_BASIS 730
- SAP_BASIS 731
- SAP_BASIS 740
- SAP_BASIS 750 to 754
Full note on SAP: SAP Support Launchpad note 2872545
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
