Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

BBPSC Cross-site scripting error, SAP security note 1058531

SAP Note 1058531

SAP security note 1058531, "BBPSC: Cross-site scripting error". Below are the symptom, SAP recommended solution and the affected software components.

ComponentSupplier Relationship Management > SRM > Technical Issues > ITS and Web files (SRM-EBP-TEC-ITS)

Description

Symptom

You create a shopping cart and specify, for example, <a ;href="javascript:alert();">Click ;me!</a> as the description of an item. When you then open this shopping cart, for example, in "Check Status" (BBPSC04), the system displays a dialog box that contains the following text: "Click me!".

Solution

Implement the following correction instructions or import the relevant Support Package.

  • For SRM 4.0: You must use SAP Basis 6.40 Support Package 13 or higher (SAPKB64013+) to manually implement the corrections using transaction SNOTE. Import such a Support Package if necessary.
  • For SRM 3.0: You must use transaction SE80 to manually implement the changes from the attachment srm30_1058531.ZIP, and then publish the relevant template. The first part of each file name specifies the internet service, followed by the name of the relevant template.

Reason and prerequisites

This problem is caused by a program error.

CVSS

Score 0

References

Affected components

  • SRM_SERVER: Versions 500, 550, 600
  • BBPCRM: Version 400

Full note on SAP: SAP Support Launchpad note 1058531

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More