SAP Security Note
High priority
SAP security note 1614750, "Update #2 to Security Notes 1466863", is a program error note released on May 8, 2012. Below are the symptom and SAP recommended solution.
Description
Symptom
Correction instructions provided for the vulnerability Reflected Cross Site Scripting (XSS) addressed in Security Note 1466863 must be corrected for the following releases:
- cFolder 4.5: till SAPK-45012INCPRXRPM
- cFolder 4.0: till SAPK-40020INCPRXRPM
- cFolder 3.1: till SAPK-31220INCPROJECT
Solution
Please apply the correction instructions to resolve the issue.
Reason and prerequisites
Security Notes 1466863 contains correction instructions which are erroneous. The implementation of Security Notes 1466863 is a prerequisite for applying this note.
CVSS
Score 0
References
Full note on SAP: SAP Support Launchpad note 1614750
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
