SAP Security Note
SAP security note 738592, “EP 5.0 Security Hotfix”, is a note released on 08.10.2009. Below are the symptom, reason and prerequisites, SAP recommended solution and the related references.
Description
Symptom
You are using SAP Portals Enterprise Portal 5.0.
Solution
Install EP 5.0 SP5 Patch 3 Hotfix 7 (or later).
This hotfix contains a number of improvements regarding user input invalidation which affects the security of your portal installation. It is strongly recommended to install this hotfix to achieve better protection against attacks via malformed URLs and other forms of injecting malicious script code into your portal applications (e.g., Cross-Site Scripting, SQL Injection, Buffer Overflow attacks).
Reason and prerequisites
You have installed EP 5.0 SP5 Patch 3.
References
- Central Note for EP 5.0 SP6 Patch 1 Hotfixes
- Central Note for EP 5.0 SP 5 Patch 3 Hotfixes
- EP 5.0: Central Note for EP-PIN-SEC (Security)
Full note on SAP: SAP Support Launchpad note 738592
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



