SAP Netweaver Multiple Vulnerabilities
BID:48351
Info
SAP Netweaver Multiple Vulnerabilities
| Bugtraq ID: | 48351 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 17 2011 12:00AM |
| Updated: | Jun 17 2011 12:00AM |
| Credit: | Alexander Polyakov and Dmitriy Evdokimov from DSecRG |
| Vulnerable: |
SAP NetWeaver 7.30 SAP NetWeaver 7.10 SAP NetWeaver 7.02 SAP NetWeaver 7.01 SAP NetWeaver 7.0 SP8 SAP NetWeaver 7.0 SP15 SAP NetWeaver 7.0 |
| Not Vulnerable: | |
Discussion
SAP Netweaver Multiple Vulnerabilities
SAP Netweaver is prone to multiple cross-site scripting vulnerabilities, an information-disclosure vulnerability, and an authentication-bypass vulnerability.
An attacker may leverage the issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, disclose sensitive information, or bypass certain security restrictions.
SAP Netweaver is prone to multiple cross-site scripting vulnerabilities, an information-disclosure vulnerability, and an authentication-bypass vulnerability.
An attacker may leverage the issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, disclose sensitive information, or bypass certain security restrictions.
Exploit / POC
SAP Netweaver Multiple Vulnerabilities
An attacker can use a web browser to exploit these issues. To exploit a cross-site scripting vulnerability, an attacker must entice an unsuspecting user to follow a malicious URI.
An attacker can use a web browser to exploit these issues. To exploit a cross-site scripting vulnerability, an attacker must entice an unsuspecting user to follow a malicious URI.
Solution / Fix
SAP Netweaver Multiple Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
SAP Netweaver Multiple Vulnerabilities
References:
References:
- [DSECRG-11-023 ] SAP NetWeaver SLD - Information Disclosure (Digital Security Research Group)
- [DSECRG-11-024 ] SAP NetWaver performanceProvierRoot - XSS (Digital Security Research Group)
- [DSECRG-11-025 ] SAP NetWeaver Trust Center Service - XSS (Digital Security Research Group)
- [DSECRG-11-026 ] SAP NetWeaver J2EE Engine - Authentication bypass (Digital Security Research Group)
- SAP NetWeaver Homepage (SAP)