SAP Security Note
Low priority
SAP security note 1141269, "Security: XSS Vulnerability in SAP GUI for HTML", is an upgrade information note released on October 8, 2009. Below are the symptom, SAP recommended solution, reason and prerequisites and the affected software components.
Description
Symptom
There is a possible XSS vulnerability in ITS/SAP GUI for HTML that may allow unauthorized script execution.
Solution
To mitigate this vulnerability, you can choose one of the following approaches:
- Update ITS: Install the latest patch level of your external ITS.
- Update SAP_BASIS: Import the latest Basis Support Package of your ITS integrated with NetWeaver.
- Apply Advanced Corrections: Implement the advanced corrections attached to this note for Release 7.00 using SNOTE.
Important: This correction may require a kernel update for integrated ITS. If the kernel is not updated as described in SAP Note 903820, no additional encoding is performed, and the issue may persist despite importing the Support Package.
Reason and prerequisites
Affected Software: SAP GUI for HTML integrated with ITS. Prerequisite: SAP GUI for HTML must be in use.
References
- SAP Note 1621946: ITS: Updated XSS-Escaping Functions
- SAP Note 903820: ITS: New Functions for XSS Prevention
Affected components
- SAP Internet Transaction Server (BC-FES-ITS)
- SAP_BASIS (Various versions)
Full note on SAP: SAP Support Launchpad note 1141269
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



