Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

EIC Cross-Site Scripting Vulnerability, SAP security note 1300128

SAP Note 1300128
SAP Security Note
Medium priority

SAP security note 1300128, “EIC: Cross-Site Scripting Vulnerability”, is a note released on 08.10.2009. Below are the symptom and SAP recommended solution.

ComponentPersonnel Management > Employee Interaction Center
PriorityMedium priority
TypeSAP Security Note
StatusReleased for Customer
Released on08.10.2009

Description

Symptom

A cross-site scripting (XSS) vulnerability exists in the Employee Interaction Center in the following views:

  • Inbox view
  • Email Preview view
  • Employee Search External Contacts view
  • Related Activities view
  • Follow-up view
  • Email Attachments view
  • Activity Contacts view
  • Activity Attachments view

Solution

Please apply the source code corrections contained in the Correction Instructions. Alternatively, apply the HR Support Package(s) indicated for your release under Reference to Support Packages.

References

Full note on SAP: SAP Support Launchpad note 1300128

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More