SAP security note 1493710, “Texts in the alert inbox are not encoded”, is a note. Below is the security information published by SAP for this note.
Description
Symptom
The system displays the texts of alerts in the alert inbox (implemented as BSP ALRTINBOX). These texts are either maintained in Customizing or may be included when alerts are triggered. These texts are displayed without encoding.
Reason and prerequisites
The alert inbox displays the alert texts without encoding them in advance.
## Solution
Implement the correction instructions using the Note Assistant or import the relevant Support Package. After applying the correction, the system will encode the texts on the alert inbox page. If you need to deactivate the encoding of the texts, follow these steps:
1. Use the maintenance view (SM30) to maintain the following value in table SXPARAMS:
| Parameter | Value | |———————|——-| | ALERT_NO_BSP_ENCODING | X |
## Affected Components
- Component: Basis Components > Basis Services/Communication Interfaces > Generic Business Tools > Alert Framework
- Software Versions:
- SAP_BASIS 620 to 640
- SAP_BASIS 700 to 702
- SAP_BASIS 710 to 730
## Support Packages
Ensure your system includes the appropriate support packages for your SAP_BASIS version. You can find the relevant support packages here.
## Correction Instructions
There are 17 correction instructions available for this note. Access them here.
## Prerequisites
- SAP_BASIS 620: Valid from 620 to 640
- SAP_BASIS 700: Valid from 700 to 702
- SAP_BASIS 710: Valid from 710 to 730
Ensure your system meets the prerequisites before applying the correction.
## Additional Resources
- Download for SNOTE
- PDF Version
Credits: Information supported by RedRays.io.
Full note on SAP: SAP Support Launchpad note 1493710
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
