SAP NetWeaver Application Server 'uddiclient/process' HTML Injection Vulnerability
BID:36034
Info
SAP NetWeaver Application Server 'uddiclient/process' HTML Injection Vulnerability
| Bugtraq ID: | 36034 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 12 2009 12:00AM |
| Updated: | Aug 21 2009 03:55PM |
| Credit: | Alexander Polyakov from Digital Security Research Group |
| Vulnerable: |
SAP NetWeaver Application Server 7.0 |
| Not Vulnerable: | |
Discussion
SAP NetWeaver Application Server 'uddiclient/process' HTML Injection Vulnerability
SAP NetWeaver Application Server is prone to an HTML-injection vulnerability because the application's UDDI client fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
This issue is documented by SAP Note 1322098.
SAP NetWeaver Application Server is prone to an HTML-injection vulnerability because the application's UDDI client fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
This issue is documented by SAP Note 1322098.
Exploit / POC
SAP NetWeaver Application Server 'uddiclient/process' HTML Injection Vulnerability
Attackers can use readily available tools to exploit this issue.
Attackers can use readily available tools to exploit this issue.
Solution / Fix
SAP NetWeaver Application Server 'uddiclient/process' HTML Injection Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
SAP NetWeaver Application Server 'uddiclient/process' HTML Injection Vulnerability
References:
References:
- [DSECRG-09-033] SAP NetWeaver Application Server (UDDI client) XSS Vulnerabil (Digital Security Research Group)
- [DSECRG-09-033] SAP Netweaver UDDI - XSS Security Vulnerability (Alexandr Polyakov
)