Reflected XSS in BSP Application CRM_THTMLB_UTIL

September 17, 2026

Reflected XSS in BSP Application CRM_THTMLB_UTIL


Impact on Business

A remote attacker can exploit a Reflected Cross-Site Scripting (XSS) vulnerability to execute arbitrary JavaScript code in the victim’s browser. This can lead to the exfiltration of sensitive user information, unauthorized modifications to the system, or redirection to malicious websites, thereby impacting the confidentiality and integrity of the application.


Vulnerability Details

The BSP Application CRM_THTMLB_UTIL contains a controller that improperly neutralizes user-supplied input before including it in the generated web page. An attacker can craft a malicious URL containing JavaScript code in specific parameters. When an authenticated victim accesses this URL, the malicious script is executed within the context of their browser, allowing the attacker to perform Cross-Site Scripting (XSS) attacks.


Solution

SAP has released SAP Note 3465129 which provides patched versions of the affected components.

The patches can be downloaded from https://me.sap.com/notes/3465129.

Onapsis strongly recommends SAP customers to download the related security fixes and apply them to the affected components in order to reduce business risks.


Report Timeline

  • 03/21/2024: Onapsis reports vulnerability to SAP
  • 06/11/2024: SAP issues the patch

References


Advisory Information

  • Public Release Date: 09/17/2026
  • Security Advisory ID: ONAPSIS-2026-0082
  • Researcher(s): Ignacio Favro

Vulnerability Information

  • Vendor: SAP
  • Affected Components: SAP NetWeaver ABAP, SAP S4 Foundation (S4FND) (Check SAP Note 3465129 for detailed information on affected releases)
  • Vulnerability Class: CWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)
  • CVSS v3 score: 6.1 (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
  • Risk Level: Medium
  • Assigned CVE: CVE-2024-34686
  • Vendor patch Information: SAP Security NOTE 3465129

Affected Components Description

  • SAP NetWeaver ABAP (Release 7.77)
  • SAP S4 Foundation (S4FND) (Release 104)

About our Research Labs

Onapsis Research Labs provides the industry analysis of key security issues that impact mission-critical systems and applications. Delivering frequent and timely security and compliance advisories with associated risk levels, Onapsis Research Labs combine in-depth knowledge and experience to deliver technical and business-context with sound security judgment to the broader information security community.

Find all reported vulnerabilities at: https://github.com/Onapsis/vulnerability_advisories

This advisory is licensed under a Creative Commons 4.0 BY-ND International License