Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Security Scan and XSS Vulnerabilities, SAP security note 1109755

SAP Note 1109755
SAP Security Note
Medium priority

SAP security note 1109755, "Security Scan and XSS Vulnerabilities", is a program error note released on 08.10.2009. Below are the symptom and SAP recommended solution.

ComponentEnterprise Portal > SAP Enterprise Portal Development Kit (PDK) > HTMLB Business for Java
CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
Version4
StatusReleased for Customer
Released on08.10.2009
LanguageEnglish

Description

Symptom

The HTMLB header parameters were vulnerable to XSS vulnerabilities.

Solution

All parameters which are passed from HTMLB are encoded so that no malicious scripts can run on the client. This fix is available in the following patches:

  • NW04 SP19
  • NW04s SP13 Patch 4
  • SP14 Patch 5
  • SP15 Patch 2
  • SP16 onwards

Reason and prerequisites

The reason for this behavior was because the parameters were not encoded.

Full note on SAP: SAP Support Launchpad note 1109755

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More