SAP Security Note
Medium priority
SAP security note 1161457, "Security Note: XSS vulnerability on Portal", is a program error note released on 08.10.2009. Below are the symptom and SAP recommended solution.
Description
Symptom
Possible vulnerability in the Portal.
Solution
The fix was submitted to NW04s on SP16 and EhP1 SP0.
Reason and prerequisites
"Cross Site Scripting" is a type of computer security vulnerability typically found in web applications which allow code injection by malicious web users into the web pages viewed by other users. To prevent vulnerability through "Cross Site Scripting", filtering functions are used when handling parameters coming from the user (browser Client). This particular fix handles a very small possibility for impact.
Full note on SAP: SAP Support Launchpad note 1161457
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



