SAP Security Note
HotNews
SAP security note 957038, "Security Gap in Cross-Site Scripting", is a program error note released on 08.10.2009. Below are the symptom and SAP recommended solution.
Description
Symptom
When you call SAP E-Recruiting, one or several URL parameters are specified. If you use the URL parameters and change a parameter in a particular way, any JavaScript code can be executed.
Reproduction steps:
- Attach the character string "%27)%3balert(%27XSS%21%27)%3b%2f%2f" (without the quotation marks) to a URL parameter (e.g., rcfSpId=9000).
- Start the application with this URL.
- Observe that the JavaScript code is executed, displaying an alert with the text "XSS!".
Solution
Import the relevant Support Package or carry out the corrections in accordance with the correction instructions.
Reason and prerequisites
This problem is due to a program error.
CVSS
Score 0
References
- 960728 – Security gap in Cross-Site-Scripting (Component: PA-ER)
- 888889 – Automatic checks for security notes using RSECNOTE (outdated) (Component: SV-SMG-SER)
Full note on SAP: SAP Support Launchpad note 957038
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
