Search This Blog

Monday, April 11, 2011

SAP Note 1334244 - Some Fields are susceptible to Cross-site scripting




Symptom
You create a shopping cart and specify Item description having javascript content. Now if your SC has error, then the error message content would be wrongly display and the behaviour would be that of how the item description javascript is executed.


Other terms
BBPSC01, BBPSC02, Description, XSS, cross-site scripting, Attachment


Reason and Prerequisites
This problem is caused by a program error. The error messages are note masked correctly.


Solution
Please apply the correction instructions or the relevant support package to resolve the issue.



Affected Releases
Software
Component
Release
From
Release
To
Release
And
subsequent
SRM_SERVER
500
500
500
 




Visit https://service.sap.com/sap/support/notes/1334244 for Correction delivered in Support Package & Corrections Instructions

No comments:

Post a Comment