SAP Security Note
Medium priority
SAP security note 1334244, "Some Fields are susceptible to Cross-site scripting", is a program error note released on October 8, 2009. Below are the symptom, SAP recommended solution, reason and prerequisites and the affected software components.
Description
Symptom
You create a shopping cart and specify an item description containing JavaScript content. If your shopping cart encounters an error, the error message content is incorrectly displayed, allowing the JavaScript in the item description to execute.
Solution
Apply the correction instructions or the relevant support package to resolve the issue.
Reason and prerequisites
This issue is caused by a program error where error messages are not properly masked.
References
This note refers to
- SAP Note 888889 – Automatic checks for security notes using RSECNOTE (outdated)
Referenced by
- SAP Note 888889 – Automatic checks for security notes using RSECNOTE (outdated)
Affected components
- SRM_SERVER 500
Full note on SAP: SAP Support Launchpad note 1334244
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



