Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Cross-site scripting error in BBP_POC, SAP security note 1267878

SAP Note 1267878

SAP security note 1267878, “Cross-site scripting error in BBP_POC”, is a note released on 08.10.2009. Below are the symptom, SAP recommended solution and reason and prerequisites.

Released on08.10.2009

Description

Symptom

You are using transaction BBP_POC (Create Purchase Order). On the initial screen, you choose the Create button. In the Purchase Order Name field, you then enter "…"" (that is, a double quotation mark), for example. After you trigger any action in this transaction, the text disappears behind the double quotation mark. This may be exploited for cross-site scripting (XSS).

Solution

Import the relevant Support Package or implement the necessary corrections. To determine which Support Package includes the fix, refer to the details below.

Manual corrections in SRM 4.0: See Note 1104301 (requires at least SAPKB64013).

Reason and prerequisites

This issue is caused by a program error in the template.

References

  • SAP Note 888889 – Automatic checks for security notes using RSECNOTE (outdated)

Full note on SAP: SAP Support Launchpad note 1267878

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More