Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Security gap in cross-site scripting, SAP security note 957038

SAP Note 957038
SAP Security Note
HotNews

SAP security note 957038, "Security Gap in Cross-Site Scripting", is a program error note released on 08.10.2009. Below are the symptom and SAP recommended solution.

ComponentPersonnel Management > E-Recruiting
CategoryProgram error
PriorityHotNews
TypeSAP Security Note
Version1
StatusReleased for Customer
Released on08.10.2009
LanguageEnglish

Description

Symptom

When you call SAP E-Recruiting, one or several URL parameters are specified. If you use the URL parameters and change a parameter in a particular way, any JavaScript code can be executed.

Reproduction steps:

  • Attach the character string "%27)%3balert(%27XSS%21%27)%3b%2f%2f" (without the quotation marks) to a URL parameter (e.g., rcfSpId=9000).
  • Start the application with this URL.
  • Observe that the JavaScript code is executed, displaying an alert with the text "XSS!".

Solution

Import the relevant Support Package or carry out the corrections in accordance with the correction instructions.

Reason and prerequisites

This problem is due to a program error.

CVSS

Score 0

References

Full note on SAP: SAP Support Launchpad note 957038

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More