High priority
SAP security note 1248870, "Security Note: XSS vulnerability on Portal", is a note released on 08.10.2009. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Possible vulnerability in the Portal.
Solution
The fix was submitted to NW04 SP23, NW04s SP18, NW04s EhP1 SP2, and NW04s EhP2 SP0.
Reason and prerequisites
“Cross Site Scripting” is a type of computer security vulnerability typically found in web applications which allow code injection by malicious web users into the web pages viewed by other users.
To prevent vulnerability through “Cross Site Scripting”, filtering functions are used for parameters from the user (browser client).
This fix handles a very small possibility for impact.
References
- SAP Note 1247019: EP-PIN: SAP NetWeaver Portal Platform NW7.0, SPs18 Central note
- SAP Note 1172412: EP-PIN: SAP NetWeaver Portal Platform NW701, Ehp1 SP2
- SAP Note 1169827: EP-PIN: Portal SP23 central note
Affected components
- EPBC from version 7.00 to 7.01+
Full note on SAP: SAP Support Launchpad note 1248870
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



