SAP Security Note
Low priority
SAP security note 1340457, “Security Note: Encoding fix for technical hidden fields”, is a program error note released on 08.10.2009. Below are the symptom and the affected software components.
Description
Symptom
SAP Security Note 1340457 addresses a potential vulnerability in the SAP Web UI related to the decoding of complex strings and the execution of JavaScript code in certain unsupported web browsers (e.g., IBM AppScan). While exploitability is considered very unlikely due to the complexity of prerequisites, this note enhances security by encoding the values of hidden fields to prevent any potential execution of dangerous parameters.
References
- SAP Note 888889 – Automatic checks for security notes using RSECNOTE (outdated)
Affected components
- CRMUIF 600
- WEBCUIF 700
- WEBCUIF 730
Full note on SAP: SAP Support Launchpad note 1340457
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
