SAP Netweaver Multiple Unspecified Cross Site Scripting and Information Disclosure Vulnerabilities
BID:47391
Info
SAP Netweaver Multiple Unspecified Cross Site Scripting and Information Disclosure Vulnerabilities
| Bugtraq ID: | 47391 |
| Class: | Serialization Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 15 2011 12:00AM |
| Updated: | Apr 28 2011 03:03PM |
| Credit: | Mariano Nunez Di Croce and Jordan Santarsieri from Onapsis |
| Vulnerable: |
SAP Web Application Server 7.0.10 SAP Web Application Server 7.0 SAP Web Application Server 6.40 SAP Web Application Server 6.20 SAP Web Application Server 6.10 SAP Web Application Server 6.40 SP21 SAP Web Application Server 6.40 SP17 SAP NetWeaver 7.30 SAP NetWeaver 7.10 SAP NetWeaver 7.02 SAP NetWeaver 7.01 SAP NetWeaver 7.0 SP8 SAP NetWeaver 7.0 SP15 SAP NetWeaver 7.0 |
| Not Vulnerable: | |
Discussion
SAP Netweaver Multiple Unspecified Cross Site Scripting and Information Disclosure Vulnerabilities
SAP Netweaver is prone to multiple unspecified cross-site scripting vulnerabilities and an information-disclosure vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks. The information-disclosure vulnerability can allow the attacker to obtain sensitive information that can aid in launching further attacks.
SAP Netweaver is prone to multiple unspecified cross-site scripting vulnerabilities and an information-disclosure vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks. The information-disclosure vulnerability can allow the attacker to obtain sensitive information that can aid in launching further attacks.
Exploit / POC
SAP Netweaver Multiple Unspecified Cross Site Scripting and Information Disclosure Vulnerabilities
The information disclosure vulnerability can be exploited with a web browser. To exploit a cross-site scripting vulnerability, an attacker must entice an unsuspecting user to follow a malicious URI.
The information disclosure vulnerability can be exploited with a web browser. To exploit a cross-site scripting vulnerability, an attacker must entice an unsuspecting user to follow a malicious URI.
Solution / Fix
SAP Netweaver Multiple Unspecified Cross Site Scripting and Information Disclosure Vulnerabilities
Solution:
Updates are available; please contact the vendor for more information.
Solution:
Updates are available; please contact the vendor for more information.
References
SAP Netweaver Multiple Unspecified Cross Site Scripting and Information Disclosure Vulnerabilities
References:
References: