SAP Fiori CVE-2018-2474 Cross Site Request Forgery Vulnerability
BID:105534
CVE-2018-2474 |Info
SAP Fiori CVE-2018-2474 Cross Site Request Forgery Vulnerability
| Bugtraq ID: | 105534 |
| Class: | Input Validation Error |
| CVE: |
CVE-2018-2474 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 09 2018 12:00AM |
| Updated: | Oct 09 2018 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
SAP HCM Fiori 1.0 |
| Not Vulnerable: | |
Discussion
SAP Fiori CVE-2018-2474 Cross Site Request Forgery Vulnerability
SAP Fiori for ERP is prone to an unspecified cross-site request-forgery vulnerability because the application fails to properly validate HTTP requests.
Exploiting this issue may allow a remote attacker to perform certain unauthorized actions and gain access to the affected application. Other attacks are also possible.
SAP Fiori 1.0 is vulnerable.
SAP Fiori for ERP is prone to an unspecified cross-site request-forgery vulnerability because the application fails to properly validate HTTP requests.
Exploiting this issue may allow a remote attacker to perform certain unauthorized actions and gain access to the affected application. Other attacks are also possible.
SAP Fiori 1.0 is vulnerable.
Exploit / POC
SAP Fiori CVE-2018-2474 Cross Site Request Forgery Vulnerability
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
Solution / Fix
SAP Fiori CVE-2018-2474 Cross Site Request Forgery Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
SAP Fiori CVE-2018-2474 Cross Site Request Forgery Vulnerability
References:
References:
- SAP Homepage (SAP)
- SAP Security Note 2688018 (SAP)
- SAP Security Note 2696889 (SAP)
- SAP Security Patch Day �?? October 2018 (SAP)