Skip links
Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

EIC Cross-Site Scripting Vulnerability, SAP security note 1300128

Description

In the Employee Interaction Center, cross-site scripting vulnerability exists in the following views:

  • Inbox view
  • Email Preview view
  • Employee Search External Contacts view
  • Related Activities view
  • Follow-up view
  • Email Attachments view
  • Activity Contacts view
  • Activity Attachments view

Available fix and Supported packages

  • EA-HRGXX | 602 | 602
  • EA-HRGXX | 603 | 603
  • EA-HRGXX | 604 | 604
  • EA-HRGXX 604 | SAPK-60406INEAHRGXX |
  • EA-HRGXX 603 | SAPK-60314INEAHRGXX |
  • EA-HRGXX 602 | SAPK-60219INEAHRGXX |
  • EA-HRGXX 602 | SAPK-60220INEAHRGXX |
  • EA-HRGXX 604 | SAPK-60407INEAHRGXX |
  • EA-HRGXX 603 | SAPK-60315INEAHRGXX |
  • EA-HRGXX 604 | SAPK-60408INEAHRGXX |
  • EA-HRGXX 602 | SAPK-60221INEAHRGXX |
  • EA-HRGXX 603 | SAPK-60316INEAHRGXX |

Affected component

    PA-EIC
    Employee Interaction Center

CVSS

Score: 0

PoC

Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.

URL

https://launchpad.support.sap.com/#/notes/1300128

TAGS

#XSS
#Cross-site-scripting-vulnerability

Explore More

Special offer for SAP Security Udemy course!

$ 9.99

Join “SAP Security Core Concepts and Security Administration” which is part of the Blackhat course series.