SAP security note 1456175, "XSS in CBS web UI", released on September 14, 2010. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A Cross-Site Scripting (XSS) vulnerability has been identified in the CBS web UI. A malicious user could exploit this vulnerability to modify displayed application content without authorization and potentially steal authentication information from other users. This could lead to session hijacking, allowing an attacker to impersonate legitimate users and gain unauthorized access to sensitive information. If an administrator’s credentials are compromised, the entire application’s security could be severely impacted.
Solution
To address this vulnerability, it is recommended to deploy the latest patch for SAPDEVINF.SCA.
References
Affected components
- DI_CBS 6.40
- SAP_DEVINF 6.40
Full note on SAP: SAP Support Launchpad note 1456175
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



