SAP J2EE Engine Core Unspecified Cross Site Scripting Vulnerability
BID:41805
Info
SAP J2EE Engine Core Unspecified Cross Site Scripting Vulnerability
| Bugtraq ID: | 41805 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 20 2010 12:00AM |
| Updated: | Jul 20 2010 12:00AM |
| Credit: | Mariano Nunez Di Croce |
| Vulnerable: |
SAP J2EE Engine Core 7.00 SAP J2EE Engine Core 6.40 |
| Not Vulnerable: | |
Discussion
SAP J2EE Engine Core Unspecified Cross Site Scripting Vulnerability
SAP J2EE Engine Core is prone to a cross-site scripting vulnerability.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site and to steal cookie-based authentication credentials.
SAP J2EE Engine Core is prone to a cross-site scripting vulnerability.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site and to steal cookie-based authentication credentials.
Exploit / POC
SAP J2EE Engine Core Unspecified Cross Site Scripting Vulnerability
An attacker can exploit this issue by enticing an unsuspecting victim to follow a malicious URI.
An attacker can exploit this issue by enticing an unsuspecting victim to follow a malicious URI.
Solution / Fix
SAP J2EE Engine Core Unspecified Cross Site Scripting Vulnerability
Solution:
Updates are available; please see the references for more information.
Solution:
Updates are available; please see the references for more information.
References
SAP J2EE Engine Core Unspecified Cross Site Scripting Vulnerability
References:
References:
- [Onapsis Security Advisory 2010-006] SAP J2EE Web Services Navigator Cross-Site (Onapsis Research Labs
) - SAP Homepage (SAP)