Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Security note, input-output validation in APO CLP, SAP security note 914920

SAP Note 914920SAP Security NoteHigh priority

SAP security note 914920, "Security note, input-output validation in APO CLP", is a program error note released on 08.10.2009. Below are the symptom, SAP recommended solution and the affected software components.

ComponentSupply Chain Management > Advanced Planning and Optimization > APO Cross Application > Collaborative Planning (SCM-APO-CA-COP)
CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
Version1
StatusReleased for Customer
Released on08.10.2009
LanguageEnglish

Description

Symptom

All Web servers that receive input parameters through HTTP requests, and then generate dynamic HTML pages and send the generated content as an answer to the client, are potentially subject to "Cross Site Scripting" (XSS) attacks.

Solution

Implement the attached correction instructions to ensure that the system validates the input parameters in the APO Collaborative Planning (CLP) applications.

Affected components

  • SCM 500

Full note on SAP: SAP Support Launchpad note 914920

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More