SAP NetWeaver Multiple Security Vulnerabilities
BID:65547
Info
SAP NetWeaver Multiple Security Vulnerabilities
| Bugtraq ID: | 65547 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 01 2014 12:00AM |
| Updated: | Feb 01 2014 12:00AM |
| Credit: | Alexander Polyakov, George Nosenko and Dmitry Chastukhin |
| Vulnerable: |
SAP NetWeaver 0 |
| Not Vulnerable: | |
Discussion
SAP NetWeaver Multiple Security Vulnerabilities
SAP NetWeaver is prone to multiple security vulnerabilities, including:
1. An information-disclosure vulnerability
2. Multiple cross-site scripting vulnerabilities
3. A denial-of-service vulnerability
Attackers can exploit these issues to obtain sensitive information, perform a denial-of-service attack, execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks.
SAP NetWeaver is prone to multiple security vulnerabilities, including:
1. An information-disclosure vulnerability
2. Multiple cross-site scripting vulnerabilities
3. A denial-of-service vulnerability
Attackers can exploit these issues to obtain sensitive information, perform a denial-of-service attack, execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks.
Exploit / POC
SAP NetWeaver Multiple Security Vulnerabilities
An attacker can exploit these issues using a web browser. To exploit the cross-site scripting issue, an attacker must entice an unsuspecting user to follow a malicious URI
An attacker can exploit these issues using a web browser. To exploit the cross-site scripting issue, an attacker must entice an unsuspecting user to follow a malicious URI
Solution / Fix
SAP NetWeaver Multiple Security Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.