• Все разделы
  • Статьи
  • Медиа
  • Новости
  • Нормативные материалы
  • Конференции
  • Глоссарий

Не установлено обновление Note 1535183

Главная Специалистам База уязвимостей Не установлено обновление Note 1535183

Карточка уязвимости

Характеристики уязвимости

Уровень опасности
Оценка CVSS
Производитель ПО
SAP
Наименование ПО
SAP Notes (1535183-2)
Описание
PY-US-PS executes certain functions through referencing specific URLs.  When an attacker tricks an authenticated user's browser into making a  request containing a certain URL and specific parameters, the function is executed with the rights of the user.
If present, the attacker may use a Cross Site Scripting attack to  trigger the exploit, or use an approach in which a link to click is presented to the victim.
Как исправить
Due to a legal change the affected BSP is no longer valid after 31.12.2010. It is switched off with note 1530008. In order to implement a correction to the security issue please implement note 1530008 or the corresponding support package.
Ссылки