SAP Security Note
SAP security note 1415148, "Missing Input Validation in Business-Explorer", is a note. Below are the symptom and SAP recommended solution.
Description
Symptom
You are using a 3.X Business Explorer (BEx) Web runtime. Cross-site scripting is possible via a displayed error message.
Solution
Implement this note or import the appropriate Support Package for your SAP BW version:
- SAP BW 3.5: Implement this SAP Note. Or import Support Package 26 for BW 3.50.
- SAP NetWeaver BI 7.00: Import Support Package 23 for SAP NetWeaver BI 7.00 (SAPKW70023) into your BI system. The Support Package is available when Note 1367799 "SAPBINews NW BI 7.0 ABAP SP23" is released for customers.
- SAP NetWeaver BI 7.01 (SAP NW BI 7.0 Enhancement Package 1): Import Support Package 06 for SAP NetWeaver BI 7.01 (SAPKW70106) into your BI system. The Support Package is available when Note 1369212 "SAPBINews NW BI 7.01 ABAP SP06" is released for customers.
- SAP NetWeaver BI 7.11: Import Support Package 05 for SAP NetWeaver BI 7.11 (SAPKW71105) into your BI system. The Support Package is available when Note 1392433 "SAPBINews NW BI 7.11 ABAP SP04" is released for customers.
- SAP NetWeaver BI 7.20: Import Support Package 03 for SAP NetWeaver BI 7.20 (SAPKW72003) into your BI system. The Support Package is available when Note 1407599 "SAPBINews NW BI 7.2 ABAP SP02" is released for customers.
In urgent cases, you can implement the correction instructions as an advance correction. You must first read Note 875986, which provides information about transaction SNOTE.
Reason and prerequisites
This problem is caused by a program error.
References
Full note on SAP: SAP Support Launchpad note 1415148
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



