Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Security XSS vulnerability in SAP GUI for HTML, SAP security note 1141269

SAP Note 1141269
SAP Security Note
Low priority

SAP security note 1141269, "Security: XSS Vulnerability in SAP GUI for HTML", is an upgrade information note released on October 8, 2009. Below are the symptom, SAP recommended solution, reason and prerequisites and the affected software components.

CategoryUpgrade information
PriorityLow priority
TypeSAP Security Note
Version13
StatusReleased for Customer
Released onOctober 8, 2009
LanguageEnglish (Master Language: German)

Description

Symptom

There is a possible XSS vulnerability in ITS/SAP GUI for HTML that may allow unauthorized script execution.

Solution

To mitigate this vulnerability, you can choose one of the following approaches:

  • Update ITS: Install the latest patch level of your external ITS.
  • Update SAP_BASIS: Import the latest Basis Support Package of your ITS integrated with NetWeaver.
  • Apply Advanced Corrections: Implement the advanced corrections attached to this note for Release 7.00 using SNOTE.

Important: This correction may require a kernel update for integrated ITS. If the kernel is not updated as described in SAP Note 903820, no additional encoding is performed, and the issue may persist despite importing the Support Package.

Reason and prerequisites

Affected Software: SAP GUI for HTML integrated with ITS. Prerequisite: SAP GUI for HTML must be in use.

References

Affected components

  • SAP Internet Transaction Server (BC-FES-ITS)
  • SAP_BASIS (Various versions)

Full note on SAP: SAP Support Launchpad note 1141269

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More