SAP SRM – XSS in tc | ~mdm | ~srmcat | ~uisearch

July 30, 2026

SAP SRM – XSS in tc\~mdm\~srmcat\~uisearch


Impact on Business

A successful Cross-Site Scripting (XSS) attack could allow an unauthenticated attacker to execute malicious scripts in the context of the victim’s browser. Depending on the victim’s privileges, this could lead to session hijacking or unauthorized actions performed on behalf of the user within the SAP SRM system, impacting the confidentiality and integrity of the application.


Vulnerability Details

The SAP SRM application contains a Reflected Cross-Site Scripting (XSS) vulnerability due to insufficient sanitization of user-supplied input in a specific query parameter. An unauthenticated attacker can craft a malicious link containing arbitrary JavaScript. If a victim is tricked into clicking the link, the malicious script is reflected back and executed within the victim’s browser session. This can be leveraged to access sensitive session information or perform actions on behalf of the victim.


Solution

SAP has released SAP Note 3588455 which provides patched versions of the affected components.

The patches can be downloaded from https://me.sap.com/notes/3588455.

Onapsis strongly recommends SAP customers to download the related security fixes and apply them to the affected components in order to reduce business risks.


Report Timeline

  • 10/04/2024: Onapsis reports vulnerability to SAP
  • 05/13/2025: SAP issues the patch

References


Advisory Information

  • Public Release Date: 07/30/2026
  • Security Advisory ID: ONAPSIS-2026-0032
  • Researcher(s): Yvan Genuer

Vulnerability Information

  • Vendor: SAP
  • Affected Components: SAP Supplier Relationship Management (SAP SRM) (Check SAP Note 3588455 for detailed information on affected releases)
  • Vulnerability Class: CWE-79: Improper Neutralization of Input During Web Page Generation
  • CVSS v3 score: 6.1 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
  • Risk Level: Medium
  • Assigned CVE: CVE-2025-43006
  • Vendor patch Information: SAP Security NOTE 3588455

Affected Components Description

The vulnerability affects SAP Supplier Relationship Management (SAP SRM) components. It was specifically identified in SAP SRM 7.0 EHP4, including associated JAVA and ABAP components. Users should consult the official SAP Security Note for a comprehensive list of all affected versions and support packages.

About our Research Labs

Onapsis Research Labs provides the industry analysis of key security issues that impact mission-critical systems and applications. Delivering frequent and timely security and compliance advisories with associated risk levels, Onapsis Research Labs combine in-depth knowledge and experience to deliver technical and business-context with sound security judgment to the broader information security community.

Find all reported vulnerabilities at: https://github.com/Onapsis/vulnerability_advisories

This advisory is licensed under a Creative Commons 4.0 BY-ND International License