Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Security Scan and XSS Vulnerabilities, SAP security note 1097591

SAP Note 1097591
SAP Security Note
High Priority

SAP security note 1097591, "Security Scan and XSS Vulnerabilities", is a program error note released on January 7, 2010. Below are the symptom and SAP recommended solution.

ComponentEnterprise Portal Development Kit (EP-PDK) > HTMLB Business for Java (EP-PDK-HBJ)
CategoryProgram Error
PriorityHigh Priority
TypeSAP Security Note
Version2
StatusReleased for Customer
Released onJanuary 7, 2010

Description

Symptom

The HTMLB header parameters were vulnerable to Cross-Site Scripting (XSS) vulnerabilities.

Solution

This issue has been fixed. Please refer to SAP Note 1109755 for more details.

Reason and prerequisites

The vulnerability arose because the parameters were not properly encoded.

Full note on SAP: SAP Support Launchpad note 1097591

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More