SAP Security Note
Medium priority
SAP security note 1300128, “EIC: Cross-Site Scripting Vulnerability”, is a note released on 08.10.2009. Below are the symptom and SAP recommended solution.
Description
Symptom
A cross-site scripting (XSS) vulnerability exists in the Employee Interaction Center in the following views:
- Inbox view
- Email Preview view
- Employee Search External Contacts view
- Related Activities view
- Follow-up view
- Email Attachments view
- Activity Contacts view
- Activity Attachments view
Solution
Please apply the source code corrections contained in the Correction Instructions. Alternatively, apply the HR Support Package(s) indicated for your release under Reference to Support Packages.
References
Full note on SAP: SAP Support Launchpad note 1300128
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
