SAP NetWeaver and Web Dynpro Java Cross-Site Scripting Vulnerability
BID:24676
Info
SAP NetWeaver and Web Dynpro Java Cross-Site Scripting Vulnerability
| Bugtraq ID: | 24676 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 27 2007 12:00AM |
| Updated: | Jun 28 2007 10:38PM |
| Credit: | Cyrill Brunschwiler is credited with the discovery of this vulnerability. |
| Vulnerable: |
SAP NetWeaver Nw04s SP9 SAP NetWeaver Nw04s SP8 SAP NetWeaver Nw04s SP7 SAP NetWeaver Nw04s SP11 SAP NetWeaver Nw04s SP10 SAP NetWeaver Nw04 SP19 SAP NetWeaver Nw04 SP18 SAP NetWeaver NW04 SP17 SAP NetWeaver Nw04 SP16 SAP NetWeaver Nw04 SP15 |
| Not Vulnerable: |
SAP Web Dynpro Runtime Core Components 700 SP12 SAP Java Technology Service 640 SP20 |
Discussion
SAP NetWeaver and Web Dynpro Java Cross-Site Scripting Vulnerability
SAP NetWeaver and Web Dynpro Java are prone to a cross-site scripting vulnerability because the applications fail to sufficiently sanitize user-supplied input.
A successful exploit of this vulnerability could allow an attacker to compromise the application, access or modify data, or steal cookie-based authentication credentials. Other attacks are also possible..
SAP NetWeaver and Web Dynpro Java are prone to a cross-site scripting vulnerability because the applications fail to sufficiently sanitize user-supplied input.
A successful exploit of this vulnerability could allow an attacker to compromise the application, access or modify data, or steal cookie-based authentication credentials. Other attacks are also possible..
Exploit / POC
SAP NetWeaver and Web Dynpro Java Cross-Site Scripting Vulnerability
To exploit this issue, an attacker must entice an unsuspecting victim into following a malicious URI.
To exploit this issue, an attacker must entice an unsuspecting victim into following a malicious URI.
Solution / Fix
SAP NetWeaver and Web Dynpro Java Cross-Site Scripting Vulnerability
Solution:
The vendor released an update to address this issues. Please contact the vendor for information on how to obtain and apply these updates.
Solution:
The vendor released an update to address this issues. Please contact the vendor for information on how to obtain and apply these updates.
References
SAP NetWeaver and Web Dynpro Java Cross-Site Scripting Vulnerability
References:
References: