SAP Security Note
Medium priority
SAP security note 1109755, "Security Scan and XSS Vulnerabilities", is a program error note released on 08.10.2009. Below are the symptom and SAP recommended solution.
Description
Symptom
The HTMLB header parameters were vulnerable to XSS vulnerabilities.
Solution
All parameters which are passed from HTMLB are encoded so that no malicious scripts can run on the client. This fix is available in the following patches:
- NW04 SP19
- NW04s SP13 Patch 4
- SP14 Patch 5
- SP15 Patch 2
- SP16 onwards
Reason and prerequisites
The reason for this behavior was because the parameters were not encoded.
Full note on SAP: SAP Support Launchpad note 1109755
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



