SAP Netweaver Cross Site Scripting and Cross Site Request Forgery Vulnerabilities
BID:56516
Info
SAP Netweaver Cross Site Scripting and Cross Site Request Forgery Vulnerabilities
| Bugtraq ID: | 56516 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 14 2012 12:00AM |
| Updated: | Nov 14 2012 12:00AM |
| Credit: | Alexander Polyakov and Alexey Tyurin from ERPScan |
| Vulnerable: |
SAP NetWeaver 7.30 SAP NetWeaver 7.10 SAP NetWeaver 7.02 SAP NetWeaver 7.01 SAP NetWeaver 7.0 SP8 SAP NetWeaver 7.0 SP15 SAP NetWeaver 7.0 EHP2 SAP NetWeaver 7.0 EHP1 SAP NetWeaver 7.0 |
| Not Vulnerable: | |
Discussion
SAP Netweaver Cross Site Scripting and Cross Site Request Forgery Vulnerabilities
SAP Netweaver is prone to a cross-site scripting vulnerability and a cross-site request-forgery vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit these vulnerabilities to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, add, delete or modify sensitive information, or perform unauthorized actions. Other attacks are also possible.
SAP Netweaver is prone to a cross-site scripting vulnerability and a cross-site request-forgery vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit these vulnerabilities to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, add, delete or modify sensitive information, or perform unauthorized actions. Other attacks are also possible.
Exploit / POC
SAP Netweaver Cross Site Scripting and Cross Site Request Forgery Vulnerabilities
To exploit these issues, an attacker must entice an unsuspecting victim to follow a malicious URI.
To exploit these issues, an attacker must entice an unsuspecting victim to follow a malicious URI.
Solution / Fix
SAP Netweaver Cross Site Scripting and Cross Site Request Forgery Vulnerabilities
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
SAP Netweaver Cross Site Scripting and Cross Site Request Forgery Vulnerabilities
References:
References:
- SAP NetWeaver Homepage (SAP)