SAP Note 1677037 - Unauthorized modification of displayed content in CRM-IFS

Component : Financial Services -

Solution : https://service.sap.com/sap/support/notes/1677037 (SAP Service marketplace login required)

Key words :
symptom application component crm-ifs, prerequisites bsp page session_buffered_frame, application component crm-ifs, sufficiently encode output parameters, modify displayed application content, cross-site scripting issue, terms cross-site scripting, potentially obtain authentification information, crm-ifs reason, cross-site scripting

Related Notes :

1582870ABAP XSS Escaping Support
1582867Security options (XSS) for ESCAPE