SAP security note 1259414, "Cross Site Scripting: PCUI Stored JavaScript Vulnerability", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Any PCUI application offering document management functionality allowing attachment of a link or an URL (such as a link to a company website or a link to a product description) to a created business transaction does not perform adequate input validation. This field inappropriately allows JavaScript to be injected into the CRM content server that may be executed in any user’s browser accessing sensitive content server data.
Solution
Appropriate encoding mechanisms have been added to prevent such attacks. Please implement the corrections attached.
Reason and prerequisites
The PCUI Framework does not perform adequate input validation with BSP application that allows a URL to be added as an attachment.
References
- 890525 – Cross-Side Scripting occurs in PCUI
- 888889 – Automatic checks for security notes using RSECNOTE (outdated)
- 822881 – XSS Support for BSP-Extensions HTMLB, XHTMLB and PHTMLB
Affected components
- SAP_ABA: from 700 to 700
- BBPCRM: from 400 to 400
Full note on SAP: SAP Support Launchpad note 1259414
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



