Dear Team
our security team findout one issue in our application URL , pls let us know if any have any idea about this one, and pls let me know how to solve it
*********************************************************************************************
[High] Cross-Site Scripting
Issue: 24631489
Severity: High
URL: https://*******.****..com:8442/irj/portal/?'==alert(32)=='
URL: https://*******.****..com:8442/irj/portal/?'==alert(491)=='
Risk(s): It is possible to steal or manipulate customer session and cookies, which might be used to impersonate a legitimate user,
allowing the hacker to view or alter user records, and to perform transactions as that user
Fix: Review possible solutions for hazardous character injection
Variant 1 of 1
The following changes were applied to the original request:
Set path to '?'==alert(32)==''
Reasoning:
Request/Response:
GET /irj/portal/ ?'==alert(32)==' HTTP/1.1
Cookie: mmcore.tst=0.142; mmid=-27883250%7CBwAAAAqjgZ9wLwoAAA%3D%3D;
mmcore.pd=928796490%7CBwAAAAoBQqOBn3AvCpmw8v4DAH47JgEf/dBIAAwAAAAXGYxjhPzQSAAAAAD/////AP//////////AAZEaXJlY3QBLwo
DAAAAAAABAAAAAAD///////////////8AAAAAAAFF; mmcore.srv=cg3.use; UnicaNIODID=Lxs1GfJnz33-YgbG5ZI;
IBM_W3SSO_ACCESS=w3-sso.toronto.ca.ibm.com%3A; PD-W3AIT-SSO-AUTH-HOSTNAME=w3-sso.toronto.ca.ibm.com%253A;
ibmSurvey=1392988909864;
com.sap.engine.security.authentication.original_application_url=GET#XDgI%2B7qhXAPBRqZKUYahHDNdZsHLbYm6PCvocq13kn0
2J3cpIZmYiMZAp1gVhI384F2FJIiB1J9mTCq3FW1Z4Ivj6kwfx5NbN6Bw7DUa69p4iBcS62sJjZByXeGSbwu3TCEO0IQfOaZM9vTFXcX24xeyeXD4
DqaVzO9CNJNuV5PovQKmNd1d2i2QBrCgrHnc; PD-W3AIT-SSO-AUTHTYPE=CDSSO; PD-W3AIT-SSO-REFPAGE=invoked; PD-W3AIT-SSOREFERER=
none; PD-W3AIT-SSO-ERR; PD-W3AIT-SSO-HOSTNAME=w3-sso.toronto.ca.ibm.com; PD-W3AIT-SSOHTTPS_
BASE=https://w3-sso.toronto.ca.ibm.com:443; PD-W3AIT-SSOID=
3sxm%2F3rcnbWuwMBuOJtOLVYZn8%2FYrnDmbdUZ6ip6UmnKZIgY8ANWa6QV%2FyAK64ZahrFFzeN2VugIJ0hu3wTeR4fFHSq
7JhoBRi8ELn8iDDqvhq2Q%2Bmz%2FxFx0BP%2FYo4t0DNBvnTeRqaq4FelyA5ntdscJskillUA38jXwYl%2BYwzzLEqe2ISzmnxi8NilJcTXhdoB5
9%2BVCWQPVh0fXGyKotokKIl79Nmq105XJ%2Bh%2FVByvyF6DSaPclsDHVNbNKjNzZJt96vQJEHFvDO4Bn%2FdLMWuUalE1LjgC68%2F5GHlgQvdD
MqW5%2BY4vS4queR0NRhro7%2FSQe%2Fn2BkOM%253D; PD-W3AIT-SSO-CDSSO-URI=https%3A%2F%2Fw3-
sso.toronto.ca.ibm.com%253A%2Fpkmscdsso%3F; PD-W3AIT-SSO-REFPAGEHOLDER=%
2FFIM%2Fsps%2FIBM_W3_SAML11_INTERNAL%2Fsaml11%2Flogin%3FSP_PROVIDER_ID%3Dhttps%3A
***************************************************************************
my question is
URL: https://*******.****..com:8442/irj/portal/?'==alert(32)=='
URL: https://*******.****..com:8442/irj/portal/?'==alert(491)=='
what is this alert (32) and alert (491)
how to solve the above security releated issue...
if any one hve idea pls help me....
thankks