SAP Security Note
High Priority
SAP security note 1097591, "Security Scan and XSS Vulnerabilities", is a program error note released on January 7, 2010. Below are the symptom and SAP recommended solution.
Description
Symptom
The HTMLB header parameters were vulnerable to Cross-Site Scripting (XSS) vulnerabilities.
Solution
This issue has been fixed. Please refer to SAP Note 1109755 for more details.
Reason and prerequisites
The vulnerability arose because the parameters were not properly encoded.
Full note on SAP: SAP Support Launchpad note 1097591
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



