SAP Netweaver Multiple Vulnerabilities
BID:48718
Info
SAP Netweaver Multiple Vulnerabilities
| Bugtraq ID: | 48718 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 19 2011 12:00AM |
| Updated: | Jul 19 2011 12:00AM |
| Credit: | Alexander Polyakov, Dmitriy Evdokimov, and Alexey Sintsov from DSecRG |
| Vulnerable: |
SAP NetWeaver 7.30 SAP NetWeaver 7.10 SAP NetWeaver 7.02 SAP NetWeaver 7.01 SAP NetWeaver 7.0 SP8 SAP NetWeaver 7.0 SP15 SAP NetWeaver 7.0 |
| Not Vulnerable: | |
Discussion
SAP Netweaver Multiple Vulnerabilities
SAP Netweaver is prone to cross-site scripting, information-disclosure, and denial-of-service vulnerabilities.
An attacker may leverage the issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, disclose sensitive information, or cause denial-of-service conditions.
SAP Netweaver is prone to cross-site scripting, information-disclosure, and denial-of-service vulnerabilities.
An attacker may leverage the issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, disclose sensitive information, or cause denial-of-service conditions.
Exploit / POC
SAP Netweaver Multiple Vulnerabilities
An attacker can use a Web browser to exploit these issues. To exploit a cross-site scripting vulnerability, an attacker must entice an unsuspecting user to follow a malicious URI.
An attacker can use a Web browser to exploit these issues. To exploit a cross-site scripting vulnerability, an attacker must entice an unsuspecting user to follow a malicious URI.
Solution / Fix
SAP Netweaver Multiple Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
SAP Netweaver Multiple Vulnerabilities
References:
References:
- [DSECRG-11-027] NetWeaver BCB �?? Missing Authorization / Information disclosure (Digital Security Research Group)
- [DSECRG-11-028] SAP NetWeaver ISpeak �?? XSS (Digital Security Research Group)
- [DSECRG-11-029] SAP NetWeaver SOAP RFC �?? Denial of Service / Integer overflow (Digital Security Research Group)
- SAP NetWeaver Homepage (SAP)