Skip links
Arpine Maghakyan

Arpine Maghakyan

Security Researcher of RedRays.

EIC Cross-Site Scripting Vulnerability, SAP security note 1300128

Description

In the Employee Interaction Center, cross-site scripting vulnerability exists in the following views:

  • Inbox view
  • Email Preview view
  • Employee Search External Contacts view
  • Related Activities view
  • Follow-up view
  • Email Attachments view
  • Activity Contacts view
  • Activity Attachments view

Available fix and Supported packages

  • EA-HRGXX | 602 | 602
  • EA-HRGXX | 603 | 603
  • EA-HRGXX | 604 | 604
  • EA-HRGXX 604 | SAPK-60406INEAHRGXX |
  • EA-HRGXX 603 | SAPK-60314INEAHRGXX |
  • EA-HRGXX 602 | SAPK-60219INEAHRGXX |
  • EA-HRGXX 602 | SAPK-60220INEAHRGXX |
  • EA-HRGXX 604 | SAPK-60407INEAHRGXX |
  • EA-HRGXX 603 | SAPK-60315INEAHRGXX |
  • EA-HRGXX 604 | SAPK-60408INEAHRGXX |
  • EA-HRGXX 602 | SAPK-60221INEAHRGXX |
  • EA-HRGXX 603 | SAPK-60316INEAHRGXX |

Affected component

    PA-EIC
    Employee Interaction Center

CVSS

Score: 0

Exploit

Exploit is not available.
For detailed information please contact the mail [email protected]

URL

https://launchpad.support.sap.com/#/notes/1300128

TAGS

#XSS
#Cross-site-scripting-vulnerability

More to explorer