SAP BusinessObjects Cross-Site Ajax Request Vulnerability
BID:100174
Info
SAP BusinessObjects Cross-Site Ajax Request Vulnerability
| Bugtraq ID: | 100174 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 08 2017 12:00AM |
| Updated: | Aug 08 2017 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
SAP BusinessObjects 0 |
| Not Vulnerable: | |
Discussion
SAP BusinessObjects Cross-Site Ajax Request Vulnerability
SAP BusinessObjects is prone to a cross-site AJAX requests vulnerability because it fails to properly sanitize user-supplied input.
Attackers can exploit these issues to obtain sensitive information, or perform unauthorized actions. This may aid in further attacks.
SAP BusinessObjects is prone to a cross-site AJAX requests vulnerability because it fails to properly sanitize user-supplied input.
Attackers can exploit these issues to obtain sensitive information, or perform unauthorized actions. This may aid in further attacks.
Exploit / POC
SAP BusinessObjects Cross-Site Ajax Request Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
SAP BusinessObjects Cross-Site Ajax Request Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
SAP BusinessObjects Cross-Site Ajax Request Vulnerability
References:
References:
- SAP Homepage (SAP)
- SAP Security Note 2381071 (SAP)
- SAP Security Patch Day �?? August 2017 (SAP)