SAP Security Note
High priority
SAP security note 887323, "HTML Encoding of Error Messages", is a note released on 08.10.2009. Below are the symptom and the SAP recommended solution.
Description
Symptom
Exception messages can contain strings influenced by form fields received from incoming HTTP requests. If these exception texts are used in outgoing HTML pages without proper encoding, it can lead to security vulnerabilities. The BSP runtime had inconsistencies in encoding these error messages.
Solution
Additional HTML encoding has been incorporated into the error handling code. It is recommended to either install these Note Assisted corrections or apply the latest Support Package that includes these changes.
Internal use: HTML encoding in CL_HTTP_EXT_BSP=>report_* methods.
References
Full note on SAP: SAP Support Launchpad note 887323
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




