SAP Security Note
High priority
SAP security note 1275278, “Security: HTML Encoding missing over the inputField tooltip”, is a note released on 08.10.2009. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
When a user enters a text that contains HTML code and there is JavaScript code in that text, under certain conditions this JavaScript code can pass through the HTTP filter that checks for dangerous content. It then can be executed the next time it is rendered.
Solution
Please implement the correction below.
Reason and prerequisites
This situation was made possible by missing HTML encoding over the inputField tooltip.
CVSS
Score 0
References
- SAP Note 1530970 – Double-encoding of tooltips
- SAP Note 888889 – Automatic checks for security notes using RSECNOTE (outdated)
Affected components
- CRMUIF: 520 to 520, 600 to 600
- WEBCUIF: 700 to 700, 730 to 730
Full note on SAP: SAP Support Launchpad note 1275278
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



