SAP Security Note
High priority
SAP security note 1416047, "Missing input validation in SLD UI pages", is a program error note released on February 10, 2010. Below are the symptom and SAP recommended solution.
Description
Symptom
When you use HTTP to call web pages, parts of the parameters for dynamic construction of these pages may be transferred. In certain situations, this can be used for cross-site scripting attacks.
Solution
Apply the relevant patches.
Reason and prerequisites
There is a danger of cross-site scripting on certain SLD user interface (UI) pages.
Full note on SAP: SAP Support Launchpad note 1416047
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
