SAP Security Note
Medium priority
SAP security note 1347929, "Unauthorized modification of displayed content in SHP", was released on December 14, 2010. Below are the symptom and SAP recommended solution.
Description
Symptom
The Shopping cart fields could be abused by a malicious user, who could modify displayed application content without authorization and potentially obtain authentication information from other legitimate users.
This vulnerability allows for code injection by malicious web users into the web pages viewed by other users, thereby preventing the transfer of critical information.
Solution
Import the relevant Support Package SAPKIBKT17 or implement the attached correction instructions available here.
Reason and prerequisites
This issue is caused by a program error where fields that can contain special characters were not correctly masked. Specifically, the shopping cart history page does not sufficiently encode input/output parameters, resulting in a reflected cross-site scripting (XSS) vulnerability.
A reflected XSS attack can be used to:
- Non-permanently deface or modify displayed content on a website.
- Steal another user’s authentication information, such as session data.
- Impersonate users, including administrators, potentially compromising application security entirely.
Affected releases: SAP SRM 5.0.
Full note on SAP: SAP Support Launchpad note 1347929
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



