Symptom
Cross-site scripting (XSS) is a type of computer security vulnerability typically found in web applications which enable malicious attackers to inject client-side script into web pages viewed by other users. An exploited cross-site scripting vulnerability can be used by attackers to bypass access controls such as the same origin policy. Their impact may range from a petty nuisance to a significant security risk, depending on the sensitivity of the data handled by the vulnerable site, and the nature of any security mitigations implemented by site owner.
Cross-site scripting vulnerabilities may happen when certain parameters are passed in the following type of URL http://<servername>:<port>/InfoViewApp/jsp/common/actionNav.faces
Read more...
Product
Keywords
XSS Cross Site Scripting Cross-site vulnerability security APPSCAN XI 3.1 SP2 javascript code injection alert , KBA , BI-BIP-ADM , BI Servers, security, Crystal Reports in Launchpad , Bug Filed
About this page
This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).Search for additional results
Visit SAP Support Portal's SAP Notes and KBA Search.
SAP Knowledge Base Article - Preview