SAP Security Note
Medium priority
SAP security note 1277948, “Input and output validation of some Web Dynpro applications”, is a program error note released on 08.10.2009. Below are the symptom and SAP recommended solution.
Description
Symptom
For some of the delivered SAP E-Recruiting Web pages (Business Server Page (BSP) or Web Dynpro), there is a potential risk of cross-site scripting (XSS) attacks. In certain areas of SAP E-Recruiting, input parameters are not adequately protected due to a program error. This note addresses and corrects this vulnerability.
Solution
- Import the Specified Support Package: Ensure you import the relevant Support Package corresponding to your software component version.
- Configure Permitted Navigation Targets: After importing the Support Package, verify that all custom SAP E-Recruiting pages are entered in the IMG activity “Store ICF Paths to Services as Permitted Navigation Targets.” This ensures that users cannot navigate to unauthorized pages, and attempts to do so will result in an error message.
CVSS
Score 0
Full note on SAP: SAP Support Launchpad note 1277948
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



