High
SAP security note 1483601, "Cross Site Scripting (XSS) FPM_TEST_CATALG possible", is a note released on December 14, 2010. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A reflected Cross-Site Scripting (XSS) vulnerability has been identified in the BSP application FPM_TEST_CATALG. This vulnerability allows malicious users to modify application content without authorization and potentially steal authentication information from other users.
An attacker exploiting this vulnerability could deface or modify displayed content on the website, steal authentication information enabling impersonation of legitimate users, and compromise the application’s security, especially if an administrator’s account is targeted.
Solution
You have two options to address this issue:
- Wait for the official Support Package that includes the fix once it is available.
- Immediately delete the BSP application
FPM_TEST_CATALGin transactionSE80. This BSP was initially used for testing purposes and is not intended for production environments.
Affected components
- SAP_ABA 701 to 702
- SAP_ABA 711 to 730
Full note on SAP: SAP Support Launchpad note 1483601
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



