SAP WebDynpro Runtime Unspecified HTML Injection Vulnerability
BID:38181
Info
SAP WebDynpro Runtime Unspecified HTML Injection Vulnerability
| Bugtraq ID: | 38181 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 11 2010 12:00AM |
| Updated: | Feb 11 2010 12:00AM |
| Credit: | Mariano Di Croce |
| Vulnerable: |
SAP NetWeaver 2004s 0 SAP NetWeaver 2004 0 |
| Not Vulnerable: |
SAP NetWeaver 2004s SP13 SAP NetWeaver 2004 SP21 |
Discussion
SAP WebDynpro Runtime Unspecified HTML Injection Vulnerability
SAP WebDynpro Runtime included in SAP NetWeaver is prone to an HTML-injection vulnerability because the application fails to sanitize user-supplied input.
Attacker-supplied HTML and script code would run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
SAP WebDynpro Runtime included in SAP NetWeaver is prone to an HTML-injection vulnerability because the application fails to sanitize user-supplied input.
Attacker-supplied HTML and script code would run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
Exploit / POC
SAP WebDynpro Runtime Unspecified HTML Injection Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
SAP WebDynpro Runtime Unspecified HTML Injection Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
SAP WebDynpro Runtime Unspecified HTML Injection Vulnerability
References:
References:
- SAP NetWeaver Homepage (SAP)
- [Onapsis Security Advisory 2010-003] SAP WebDynpro Runtime XSS/CSS Injection (Onapsis Research Labs
)