Low priority
SAP security note 1077910, "Further cross-site scripting errors", was released on 08.10.2009. Below are the SAP recommended solution and the affected software components.
Description
Solution
To resolve this issue, you should either import the relevant Support Package or implement the provided correction instructions.
For manual corrections in SRM 4.0, refer to Note 1104301 (requires at least SAPKB64013).
References
Affected components
- SRM_SERVER 500
- SRM_SERVER 550
Full note on SAP: SAP Support Launchpad note 1077910
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



