Solution : https://service.sap.com/sap/support/notes/788771 (SAP Service marketplace login required)
Key words :
cross site scripting [xss], html special character  , der bsp application 'hrrcf_unrg_srch', %>   <%= controller->p_hits %>  , cross site scripting, <%= controller->p_hits %>  , bsp-applikation 'hrrcf_unrg_srch', %> <%= controller->p_hits %> <%= otr, %> <%= controller->p_hits %> <%= otr, %> <%= controller->p_hits %> <%= otr
Related Notes :
782567 | Cross Site Scripting (XSS) |