SAP security note 1267878, “Cross-site scripting error in BBP_POC”, is a note released on 08.10.2009. Below are the symptom, SAP recommended solution and reason and prerequisites.
Description
Symptom
You are using transaction BBP_POC (Create Purchase Order). On the initial screen, you choose the Create button. In the Purchase Order Name field, you then enter "…"" (that is, a double quotation mark), for example. After you trigger any action in this transaction, the text disappears behind the double quotation mark. This may be exploited for cross-site scripting (XSS).
Solution
Import the relevant Support Package or implement the necessary corrections. To determine which Support Package includes the fix, refer to the details below.
Manual corrections in SRM 4.0: See Note 1104301 (requires at least SAPKB64013).
Reason and prerequisites
This issue is caused by a program error in the template.
References
- SAP Note 888889 – Automatic checks for security notes using RSECNOTE (outdated)
Full note on SAP: SAP Support Launchpad note 1267878
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



