SAP Security Note
HotNews
SAP security note 1022102, "Executing JavaScripts in logon data", was released on October 8, 2009. Below are the SAP recommended solution and the affected software components.
Description
Solution
To address this vulnerability, you can use one of the following methods:
- Register a custom logon error page: use transaction SICF to register your own logon error page, such as for the "default_host" service.
- Apply Support Packages or source corrections: import the relevant Support Package or implement the source corrections provided with this note.
This security note addresses a potential XSS vulnerability in the ICF logon routine. It is recommended to apply the necessary corrections promptly to secure your SAP systems.
References
Affected components
- SAP_BASIS 640
- SAP_BASIS 700
Full note on SAP: SAP Support Launchpad note 1022102
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
