SAP Security Note
High priority
SAP security note 1177437, "Cross Side Scripting issue with Internet Sales", is a program error note released on 08.10.2009. Below are the symptom and the SAP recommended solution.
Description
Symptom
Certain Cross Side Scripting (XSS) issues have been recently discovered in the Internet Sales Application. This affects both B2B and B2C platforms.
Solution
For CRM 5.0, apply CRM ECommerce 5.0 SP11 patch 28 or higher. This note is released only for SAP CRM WebChannel.
The changes became available during Calendar Week 24, from 9th May to 10th June. The correction is included in the attached Service Package as of Release 5.0. Refer to SAP Note 877887 for instructions on obtaining the patch, available on the SAP Service Marketplace or via the Solution Manager.
This document is causing the following side effect: 1328184 – Impossible to access webchannel application in Chinese.
Reason and prerequisites
Program Error.
Full note on SAP: SAP Support Launchpad note 1177437
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




