Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Extended security enhancements to prevent XSS vulnerability, SAP security note 1164539

SAP Note 1164539
HotNews

SAP security note 1164539, “Extended security enhancements to prevent XSS vulnerability”, is a program error note released on October 8, 2009. Below are the symptom and SAP recommended solution.

ComponentCRM-ISA
CategoryProgram error
PriorityHotNews
StatusReleased for Customer
Released onOctober 8, 2009

Description

Symptom

This note contains extended security enhancements to prevent cross-site scripting (XSS) vulnerability in E-Commerce solutions release 5.0, 5.2, and 6.0.

Solution

Released for SAP CRM WebChannel / SAP E-Commerce (for SAP ERP). The changes are available as of Calendar Week 3, January 12th, 2009 to January 16th, 2009. The correction is available in the attached Service Package as of Release 5.0. Note 877887 describes how you can obtain the patch currently available on the SAP Service Marketplace (or now from the Solution Manager).

References

Full note on SAP: SAP Support Launchpad note 1164539

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More