Skip links
Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

URL in Launchpad-Navigation can be malformed, SAP security note 1659015

Description

The URL of a launchpad navigation target can be misused for cross side scripting. The navigation parameters in the URL are not sufficiently encoded, resulting in a reflected cross-site scripting issue.
Cross-site scripting (XSS) is a type of computer security vulnerability typically found in web applications which enable malicious attackers to inject client-side script into web pages viewed by other users. An exploited cross-site scripting vulnerability can be used by attackers to bypass access controls such as the same origin policy. Their impact may range from a petty nuisance to a significant security risk, depending on the sensitivity of the data handled by the vulnerable site, and the nature of any security mitigations implemented by site owner.
Cross-site scripting vulnerabilities may happen when certain parameters are passed in a URL of a launchpad target navigation

Available fix and Supported packages

  • SAP_BS_FND | 731 | 731
  • SAP_BS_FND | 746 | 746
  • SAP_BS_FND 731 | SAPK-73102INSAPBSFND |
  • SAP_BS_FND 746 | 746 |

Affected component

    CA-EPT-ANL-LST
    Analytics List Component for Floorplan Manager

CVSS

Score: 0

PoC

Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.

URL

https://launchpad.support.sap.com/#/notes/1659015

TAGS

#XSS
#Cross-Site-Scripting
#Cross-site
#vulnerability
#security
#BS_ANLY_CHART_UIBB
#WDC_BS_ANLY_LIST_ALV.

Explore More

RedRays AI for ABAP Code Security

Empowering Secure, Efficient, and Compliant SAP ABAP Development—in Real Time and Without Data Retention In today’s rapidly evolving business landscape, organizations increasingly

Special offer for SAP Security Udemy course!

$ 9.99

Join “SAP Security Core Concepts and Security Administration” which is part of the Blackhat course series.