SAP security note 1411659, "Security fixes for SRM SUS, Vendor Evaluation, SRM ROS". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A critical security vulnerability exists in the SAP Supplier Relationship Management (SRM) solution, specifically affecting the SRM Supplier Self-Services (SRM SUS), Vendor Evaluation (SRM VE), and Registration of Supplier (SRM ROS) applications. This vulnerability allows attackers to perform Cross-Site Scripting (XSS) attacks by injecting malicious HTML or JavaScript code into input fields. When a legitimate user accesses the compromised pages, the malicious scripts execute, potentially leading to data theft or unauthorized actions without the user’s knowledge.
Solution
To mitigate this vulnerability, apply the corrections provided in SAP Note 1411659 or the appropriate Support Package. The primary fix involves implementing HTML encoding of input fields to prevent the execution of injected scripts. If your SRM installation runs on BASIS 6.40 or below, it’s recommended to upgrade your SRM system and apply the latest support packages, as the corrections in this note will not be automatically applied and require manual intervention.
Affected components
- SAP SRM 4.0
- SAP SRM 5.0
- SAP SRM 6.0
- SAP SRM 7.0
Full note on SAP: SAP Support Launchpad note 1411659
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



