Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Cross Site ScriptingPCUI Stored JavaScript Vulnerability, SAP security note 1259414

SAP Note 1259414

SAP security note 1259414, "Cross Site Scripting: PCUI Stored JavaScript Vulnerability", is a note. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

Any PCUI application offering document management functionality allowing attachment of a link or an URL (such as a link to a company website or a link to a product description) to a created business transaction does not perform adequate input validation. This field inappropriately allows JavaScript to be injected into the CRM content server that may be executed in any user’s browser accessing sensitive content server data.

Solution

Appropriate encoding mechanisms have been added to prevent such attacks. Please implement the corrections attached.

Reason and prerequisites

The PCUI Framework does not perform adequate input validation with BSP application that allows a URL to be added as an attachment.

References

Affected components

  • SAP_ABA: from 700 to 700
  • BBPCRM: from 400 to 400

Full note on SAP: SAP Support Launchpad note 1259414

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More