SAP security note 1363788, "Security Note: Vulnerable Page Builder", is a note. Below are the symptom and SAP recommended solution.
Description
Symptom
Security Note: A security issue was found in the portal’s Page Builder component. Parameters were vulnerable to XSS vulnerabilities.
Solution
All parameters passed from the Page Builder are now encoded to prevent malicious scripts from running on the client side. The fix is available in the following versions:
- NW04 SP25
- NW04s SP21
- NW04s EhP 1 (7.01) SP6
- NW04s EhP 2 (7.02) SP2
Reason and prerequisites
Parameters in the IFrame built by the Page Builder were not encoded.
Full note on SAP: SAP Support Launchpad note 1363788
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



