SAP security note 1702930, "Enterprise Workspaces XSS Encoding Library – StringUtils", addresses the following vulnerability. Below are the symptom, SAP recommended solution, references and the affected software components.
Description
Symptom
A reflected cross-site scripting (XSS) vulnerability has been identified in SAP Enterprise Workspaces. Malicious users can exploit this vulnerability to modify displayed application content without authorization and potentially steal authentication information from legitimate users. This could allow attackers to impersonate users, including administrators, thereby compromising the security of the application.
- Modify or deface displayed content on the web application temporarily.
- Steal authentication information to impersonate users, potentially gaining unauthorized access to sensitive data and administrative controls.
Solution
To address this vulnerability, apply the relevant support package patch from the "Support Package Patches" section of the note. Ensure you are using the latest patch level for your specific software component version. Refer to SAP Note 866020 for the updated XSS Encoding guide.
References
- 1693080 – Technical adjustments on encoding handling in EP
- 1625557 – Central Note for Enterprise Workspaces 1.1 SP01
- 1622964 – Known Issues of Enterprise Workspaces 1.1 SP01
- 1615941 – Portal XSS Encoding Library – StringUtils
- 1568612 – Central Note for Enterprise Workspaces 1.0 SP03
- 1529975 – Central Note for Enterprise Workspaces 1.0 SP02
- 1519576 – Central Note for Enterprise Workspaces 1.0 SP01
- 1476083 – Central Note for Enterprise Workspaces 1.0 SP00
Affected components
- Enterprise Portal > Enterprise Workspaces On Premise > EP-EWP-RT (versions 1.00, 1.1700, 1.1730 for SPACES and SPACES-KM; 1.0, 1.1700, 1.1730 for EP-EXT)
Full note on SAP: SAP Support Launchpad note 1702930
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




