SAP security note 1058531, "BBPSC: Cross-site scripting error". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
You create a shopping cart and specify, for example, <a ;href="javascript:alert();">Click ;me!</a> as the description of an item. When you then open this shopping cart, for example, in "Check Status" (BBPSC04), the system displays a dialog box that contains the following text: "Click me!".
Solution
Implement the following correction instructions or import the relevant Support Package.
- For SRM 4.0: You must use SAP Basis 6.40 Support Package 13 or higher (SAPKB64013+) to manually implement the corrections using transaction SNOTE. Import such a Support Package if necessary.
- For SRM 3.0: You must use transaction SE80 to manually implement the changes from the attachment srm30_1058531.ZIP, and then publish the relevant template. The first part of each file name specifies the internet service, followed by the name of the relevant template.
Reason and prerequisites
This problem is caused by a program error.
CVSS
Score 0
References
This note refers to
Affected components
- SRM_SERVER: Versions 500, 550, 600
- BBPCRM: Version 400
Full note on SAP: SAP Support Launchpad note 1058531
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
