SAP security note 1052053, "Security: XSS Vulnerability in ITS 6.20". Below are the symptom and SAP recommended solution.
Description
Symptom
ITS 6.20 has a Cross-Site Scripting (XSS) vulnerability. By creating a specially crafted URL, it is possible to execute JavaScript in the context of the ITS login page. With this URL, an attacker cannot log on to the SAP system.
Solution
Apply ITS 6.20 Patch 25.
Reason and prerequisites
This vulnerability affects ITS 6.20 from patch 15 up to patch 24.
Full note on SAP: SAP Support Launchpad note 1052053
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



