SAP NetWeaver System Landscape Directory Multiple Cross Site Scripting Vulnerabilities
BID:41913
Info
SAP NetWeaver System Landscape Directory Multiple Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 41913 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 13 2010 12:00AM |
| Updated: | Jul 13 2010 12:00AM |
| Credit: | Alexander Polyakov, Alexey Troshichev, Digital Security Research Group [DSecRG] |
| Vulnerable: |
SAP NetWeaver 7.02 SAP NetWeaver 7.01 SAP NetWeaver 7.0 SP8 SAP NetWeaver 7.0 SP15 SAP NetWeaver 7.0 SAP NetWeaver 6.4 |
| Not Vulnerable: | |
Discussion
SAP NetWeaver System Landscape Directory Multiple Cross Site Scripting Vulnerabilities
The System Landscape Directory of SAP NetWeaver is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied input
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
NetWeaver 6.4 through 7.02 are vulnerable.
The System Landscape Directory of SAP NetWeaver is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied input
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
NetWeaver 6.4 through 7.02 are vulnerable.
Exploit / POC
SAP NetWeaver System Landscape Directory Multiple Cross Site Scripting Vulnerabilities
Attackers can exploit these issues by enticing an unsuspecting user to follow a malicious URI.
Attackers can exploit these issues by enticing an unsuspecting user to follow a malicious URI.
Solution / Fix
SAP NetWeaver System Landscape Directory Multiple Cross Site Scripting Vulnerabilities
Solution:
These issues have been fixed. Please see the references for details.
Solution:
These issues have been fixed. Please see the references for details.
References
SAP NetWeaver System Landscape Directory Multiple Cross Site Scripting Vulnerabilities
References:
References:
- [DSECRG-09-068] SAP NetWeaver SLD - Multiple XSS (Digital Security)
- Fix for SAP NetWeaver SLD - Multiple XSS (SAP)
- SAP Homepage (SAP)
- System Landscape Directory (SAP)
- [DSECRG-09-068] SAP NetWaver SLD - multiple XSS (Alexandr Polyakov)