Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Security Note XSS vulnerability on Portal, SAP security note 1161457

SAP Note 1161457
SAP Security Note
Medium priority

SAP security note 1161457, "Security Note: XSS vulnerability on Portal", is a program error note released on 08.10.2009. Below are the symptom and SAP recommended solution.

ComponentEnterprise Portal > SAP Enterprise Portal (On Premise) > Portal Runtime
CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
Version2
StatusReleased for Customer
Released on08.10.2009
LanguageEnglish

Description

Symptom

Possible vulnerability in the Portal.

Solution

The fix was submitted to NW04s on SP16 and EhP1 SP0.

Reason and prerequisites

"Cross Site Scripting" is a type of computer security vulnerability typically found in web applications which allow code injection by malicious web users into the web pages viewed by other users. To prevent vulnerability through "Cross Site Scripting", filtering functions are used when handling parameters coming from the user (browser Client). This particular fix handles a very small possibility for impact.

Full note on SAP: SAP Support Launchpad note 1161457

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More