SAP security note 1161008, "Security Note: XSS in KM external links". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
One can perform XSS attack in KM by providing as an external link target malicious scripting.
Solution
A. The issue is cleared in these deliveries:
- Patch 2 for SP 22 of Content Management + Collaboration 6.0 640
- SAP NetWeaver 04 SP 23 and up
- SAP NetWeaver 7.0 (formerly named 2004s) SP 16 and up
B. Possible workaround before the release of the mentioned deliveries:
- There is no workaround possible.
Reason and prerequisites
The text that is entered as an external link target is directly provided to the browser window that is opened when the link is accessed.
The fix affects:
- Newly created external links.
- External links whose target has been updated.
Affected components
- SAP NetWeaver 04 up to SP 22
- SAP NetWeaver 7.0 (formerly named 2004s) up to SP15
Full note on SAP: SAP Support Launchpad note 1161008
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



