SAP Security Note
Low priority
SAP security note 985559, "XXS vulnerability", was released on 08.10.2009. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
There is an XSS vulnerability in the following error pages:
- cmdinvalidcommand.html
- cmdparameterinvalid.html
- cmdparametermissing.html
- commandexecfailed.html
- invalidservice.html
Solution
The error was eliminated in ITS 6.20 Patch 23.
CVSS
Score 0
Affected components
- BC-FES-ITS: 620 to 620
Full note on SAP: SAP Support Launchpad note 985559
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



