SAP security note 1321116, "Security Note: Cross site scripting via CurrentFocusID", is a note. Below are the symptom, SAP recommended solution and reason and prerequisites.
Description
Symptom
WebDynpro applications have a security vulnerability that allows Cross Site Scripting (XSS) via CurrentFocusID.
Solution
The issue has been resolved by properly escaping the CurrentFocusID on the server side. The fix is available in the upcoming Support Packages for the following releases:
- NW 6.40, SP24 and above
- NW 7.00, SP19 and above
- NW 7.01, SP04 and above
- NW 7.02, SP00 and above
- NW 7.10, SP08 and above
- NW 7.11, SP02 and above
Additionally, patches are available for the following releases:
- NW 7.00, SP15 (Refer to note 1138102) – SAPJTECHS15P patch level 15, SAPJTECHF15P patch level 14
- NW 7.00, SP16 (Refer to note 1226726) – SAPJTECHS16P patch level 16, SAPJTECHF16P patch level 14
- NW 7.00, SP17 (Refer to note 1248027) – SAPJTECHS17P patch level 06, SAPJTECHF17P patch level 05
- NW 7.00, SP18 (Refer to note 1291752) – SAPJTECHS18P patch level 3, SAPJTECHF18P patch level 3
- NW 7.11, SP01 (Refer to upcoming notes)
Note 1: The note number and patch number for NW 7.11, SP01 will be updated once available.
Note 2: For NW 6.40 SP24 and above, the software archive is delivered as a .SAR file. In the download region, look for the file with the description "J2EERT24" (For SP24).
Reason and prerequisites
In WebDynpro, the CurrentFocusID sent from the client was not properly escaped on the server side before it was sent back to the client. This vulnerability allows an attacker to inject malicious JavaScript code into the response of WebDynpro applications.
Full note on SAP: SAP Support Launchpad note 1321116
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



