SAP security note 914920, "Security note, input-output validation in APO CLP", is a program error note released on 08.10.2009. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
All Web servers that receive input parameters through HTTP requests, and then generate dynamic HTML pages and send the generated content as an answer to the client, are potentially subject to "Cross Site Scripting" (XSS) attacks.
Solution
Implement the attached correction instructions to ensure that the system validates the input parameters in the APO Collaborative Planning (CLP) applications.
Affected components
- SCM 500
Full note on SAP: SAP Support Launchpad note 914920
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



