SAP Web Application Server WEBRFC ICF Service Cross-Site Scripting Vulnerability
BID:49646
Info
SAP Web Application Server WEBRFC ICF Service Cross-Site Scripting Vulnerability
| Bugtraq ID: | 49646 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 14 2011 12:00AM |
| Updated: | Sep 14 2011 12:00AM |
| Credit: | Mariano Nuñez Di Croce |
| Vulnerable: |
SAP Web Application Server 7.0 |
| Not Vulnerable: | |
Discussion
SAP Web Application Server WEBRFC ICF Service Cross-Site Scripting Vulnerability
SAP Web Application Server is prone to a cross-site scripting vulnerability because the application fails to sufficiently sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and to launch other attacks.
SAP Web Application Server 7.0 is vulnerable; other versions may also be affected.
SAP Web Application Server is prone to a cross-site scripting vulnerability because the application fails to sufficiently sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and to launch other attacks.
SAP Web Application Server 7.0 is vulnerable; other versions may also be affected.
Exploit / POC
SAP Web Application Server WEBRFC ICF Service Cross-Site Scripting Vulnerability
To exploit this issue, an attacker must entice an unsuspecting victim into following a malicious URI.
To exploit this issue, an attacker must entice an unsuspecting victim into following a malicious URI.
Solution / Fix
SAP Web Application Server WEBRFC ICF Service Cross-Site Scripting Vulnerability
Solution:
Updates are available. Please see the references for more details.
Solution:
Updates are available. Please see the references for more details.
References
SAP Web Application Server WEBRFC ICF Service Cross-Site Scripting Vulnerability
References:
References:
- [Onapsis Security Advisory 2011-015] SAP WebAS webrfc Cross-Site Scripting (Onapsis Research Labs)
- SAP Homepage (SAP)
- [Onapsis Security Advisory 2011-015] SAP WebAS webrfc Cross-Site Scripting (Onapsis Research Labs)