SAP Security Note
HotNews
SAP security note 1268340, “Extended security enhancements to prevent XSS vulnerability”, is a program error note released on 08.10.2009. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
This note contains extended security enhancements to prevent cross-site scripting (XSS) vulnerabilities in E-Commerce solutions release 4.0.
Solution
This note is released only for E-Commerce 4.0. The changes are available from Calendar Week 46, 3rd to 7th November and are included in ISA 4.0 Service Package 15 Patch 3.
Upgrade your application by downloading the latest ISA/ICSS patch from the SAP Service Marketplace and replacing the existing Java file with the newest version and clearing the work folder.
If using SAP J2EE Engine 6.40, follow the steps described in Note 887692.
References
This note refers to
- SAP Note 1262675 – J2EE engine filter to check for XSS input
Referenced by
- SAP Note 1288856 – Blank JSP page during order simulation
Affected components
- SAP-CRMICS 4.0_640 to 4.0_640
- SAP-CRMISA 4.0_640 to 4.0_640
Full note on SAP: SAP Support Launchpad note 1268340
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




