SAP Netweaver 'server' Parameter Cross Site Scripting Vulnerability
BID:49266
CVE-2011-5263 |Info
SAP Netweaver 'server' Parameter Cross Site Scripting Vulnerability
| Bugtraq ID: | 49266 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-5263 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 19 2011 12:00AM |
| Updated: | Feb 14 2013 12:21PM |
| Credit: | Dmitriy Evdokimov, Digital Security Research Group (DSecRG) |
| Vulnerable: |
SAP NetWeaver 7.30 SAP NetWeaver 7.10 SAP NetWeaver 7.02 SAP NetWeaver 7.01 SAP NetWeaver 7.0 SP8 SAP NetWeaver 7.0 SP15 SAP NetWeaver 7.0 |
| Not Vulnerable: | |
Discussion
SAP Netweaver 'server' Parameter Cross Site Scripting Vulnerability
SAP Netweaver is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
SAP Netweaver is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
Exploit / POC
SAP Netweaver 'server' Parameter Cross Site Scripting Vulnerability
To exploit a cross-site scripting vulnerability, an attacker must entice an unsuspecting victim to follow a malicious URI.
To exploit a cross-site scripting vulnerability, an attacker must entice an unsuspecting victim to follow a malicious URI.
Solution / Fix
SAP Netweaver 'server' Parameter Cross Site Scripting Vulnerability
Solution:
The vendor has released an update. Please see the references for details.
Solution:
The vendor has released an update. Please see the references for details.
References
SAP Netweaver 'server' Parameter Cross Site Scripting Vulnerability
References:
References:
- [DSECRG-11-030] SAP NetWaver JavaMailExamples - XSS (Digital Security Research Group)
- SAP NetWeaver Homepage (SAP)
- SAP Advisory (SAP)