PT-2023-2940 · Sap · Sap Crm Webclient Ui
Published
2023-05-09
·
Updated
2023-05-12
·
CVE-2023-29188
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
SAP CRM WebClient UI versions SAPSCORE 129, S4FND 102 through S4FND 107, WEBCUIF 701 through WEBCUIF 801
Description
The SAP CRM WebClient UI does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) issue. After successful exploitation, an attacker with user-level access can read and modify some sensitive information but cannot delete the data. The vulnerability exists due to inadequate protection of the web page structure, allowing a remote attacker to conduct an XSS attack.
Recommendations
For SAP CRM WebClient UI versions SAPSCORE 129, S4FND 102 through S4FND 107, and WEBCUIF 701 through WEBCUIF 801, consider implementing proper input encoding to prevent XSS attacks. As a temporary workaround, restrict access to sensitive information and monitor user activity to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Crm Webclient Ui