HotNews
SAP security note 1164539, “Extended security enhancements to prevent XSS vulnerability”, is a program error note released on October 8, 2009. Below are the symptom and SAP recommended solution.
Description
Symptom
This note contains extended security enhancements to prevent cross-site scripting (XSS) vulnerability in E-Commerce solutions release 5.0, 5.2, and 6.0.
Solution
Released for SAP CRM WebChannel / SAP E-Commerce (for SAP ERP). The changes are available as of Calendar Week 3, January 12th, 2009 to January 16th, 2009. The correction is available in the attached Service Package as of Release 5.0. Note 877887 describes how you can obtain the patch currently available on the SAP Service Marketplace (or now from the Solution Manager).
References
Full note on SAP: SAP Support Launchpad note 1164539
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
