SAP Web Application Server '/sap/bc/gui/sap/its/webgui/' Cross-Site Scripting Vulnerability
BID:29317
Info
SAP Web Application Server '/sap/bc/gui/sap/its/webgui/' Cross-Site Scripting Vulnerability
| Bugtraq ID: | 29317 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-2421 |
| Remote: | Yes |
| Local: | No |
| Published: | May 21 2008 12:00AM |
| Updated: | May 07 2015 05:28PM |
| Credit: | Digital Security Research Group [DSecRG] |
| Vulnerable: |
SAP Web Application Server 7.0 |
| Not Vulnerable: | |
Discussion
SAP Web Application Server '/sap/bc/gui/sap/its/webgui/' Cross-Site Scripting Vulnerability
SAP Web Application Server is prone to a cross-site scripting vulnerability because the application fails to sufficiently sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
SAP Web Application Server 7.0 is vulnerable; other versions may also be affected.
SAP Web Application Server is prone to a cross-site scripting vulnerability because the application fails to sufficiently sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
SAP Web Application Server 7.0 is vulnerable; other versions may also be affected.
Exploit / POC
SAP Web Application Server '/sap/bc/gui/sap/its/webgui/' Cross-Site Scripting Vulnerability
To exploit this issue, an attacker must entice an unsuspecting victim into following a malicious URI.
The following example URI is available:
To exploit this issue, an attacker must entice an unsuspecting victim into following a malicious URI.
The following example URI is available:
Solution / Fix
SAP Web Application Server '/sap/bc/gui/sap/its/webgui/' Cross-Site Scripting Vulnerability
Solution:
Reports indicate that the vendor has addressed this issue, but this has not been confirmed. Please contact the vendor for more information.
Solution:
Reports indicate that the vendor has addressed this issue, but this has not been confirmed. Please contact the vendor for more information.
References
SAP Web Application Server '/sap/bc/gui/sap/its/webgui/' Cross-Site Scripting Vulnerability
References:
References:
- Vendor Homepage (SAP)
- [DSECRG-08-023] SAP Web Application Server XSS Security Vulnerability (Digital Security Research Group
)