SAP SRM – XSS in tc\~mdm\~srmcat\~uisearch
Impact on Business
A successful Cross-Site Scripting (XSS) attack could allow an unauthenticated attacker to execute malicious scripts in the context of the victim’s browser. Depending on the victim’s privileges, this could lead to session hijacking or unauthorized actions performed on behalf of the user within the SAP SRM system, impacting the confidentiality and integrity of the application.
Vulnerability Details
The SAP SRM application contains a Reflected Cross-Site Scripting (XSS) vulnerability due to insufficient sanitization of user-supplied input in a specific query parameter. An unauthenticated attacker can craft a malicious link containing arbitrary JavaScript. If a victim is tricked into clicking the link, the malicious script is reflected back and executed within the victim’s browser session. This can be leveraged to access sensitive session information or perform actions on behalf of the victim.
Solution
SAP has released SAP Note 3588455 which provides patched versions of the affected components.
The patches can be downloaded from https://me.sap.com/notes/3588455.
Onapsis strongly recommends SAP customers to download the related security fixes and apply them to the affected components in order to reduce business risks.
Report Timeline
- 10/04/2024: Onapsis reports vulnerability to SAP
- 05/13/2025: SAP issues the patch
References
Advisory Information
- Public Release Date: 07/30/2026
- Security Advisory ID: ONAPSIS-2026-0032
- Researcher(s): Yvan Genuer
Vulnerability Information
- Vendor: SAP
- Affected Components: SAP Supplier Relationship Management (SAP SRM) (Check SAP Note 3588455 for detailed information on affected releases)
- Vulnerability Class: CWE-79: Improper Neutralization of Input During Web Page Generation
- CVSS v3 score: 6.1 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
- Risk Level: Medium
- Assigned CVE: CVE-2025-43006
- Vendor patch Information: SAP Security NOTE 3588455
Affected Components Description
The vulnerability affects SAP Supplier Relationship Management (SAP SRM) components. It was specifically identified in SAP SRM 7.0 EHP4, including associated JAVA and ABAP components. Users should consult the official SAP Security Note for a comprehensive list of all affected versions and support packages.

About our Research Labs
Onapsis Research Labs provides the industry analysis of key security issues that impact mission-critical systems and applications. Delivering frequent and timely security and compliance advisories with associated risk levels, Onapsis Research Labs combine in-depth knowledge and experience to deliver technical and business-context with sound security judgment to the broader information security community.
Find all reported vulnerabilities at: https://github.com/Onapsis/vulnerability_advisories
This advisory is licensed under a Creative Commons 4.0 BY-ND International License
