Solution : https://service.sap.com/sap/support/notes/1441953 (SAP Service marketplace login required)
Key words : 
reflexive cross-site scripting, web dynpro abap pages, web dynpro abap, input parameters sufficiently, relevant support package, logon data, administration user, entire application, solution implement, correction instructions
Related Notes : 
       
| 888889 | Automatic checks for security notes using RSECNOTE |