Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Input and output validation of some Web Dynpro applications, SAP security note 1277948

SAP Note 1277948
SAP Security Note
Medium priority

SAP security note 1277948, “Input and output validation of some Web Dynpro applications”, is a program error note released on 08.10.2009. Below are the symptom and SAP recommended solution.

ComponentPersonnel Management > E-Recruiting (PA-ER)
CategoryProgram error
PriorityMedium priority
TypeSAP Security Note
Version3
StatusReleased for Customer
Released on08.10.2009
LanguageEnglish

Description

Symptom

For some of the delivered SAP E-Recruiting Web pages (Business Server Page (BSP) or Web Dynpro), there is a potential risk of cross-site scripting (XSS) attacks. In certain areas of SAP E-Recruiting, input parameters are not adequately protected due to a program error. This note addresses and corrects this vulnerability.

Solution

  • Import the Specified Support Package: Ensure you import the relevant Support Package corresponding to your software component version.
  • Configure Permitted Navigation Targets: After importing the Support Package, verify that all custom SAP E-Recruiting pages are entered in the IMG activity “Store ICF Paths to Services as Permitted Navigation Targets.” This ensures that users cannot navigate to unauthorized pages, and attempts to do so will result in an error message.

CVSS

Score 0

Full note on SAP: SAP Support Launchpad note 1277948

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More