• Все разделы
  • Статьи
  • Медиа
  • Новости
  • Нормативные материалы
  • Конференции
  • Глоссарий

Note 1630309 - Unauthorized modification in BSP application in CRM-IC-FRW

Главная Специалистам База уязвимостей Note 1630309 - Unauthorized modification in BSP application in CRM-IC-FRW

Карточка уязвимости

Характеристики уязвимости

Уровень опасности
Оценка CVSS
Производитель ПО
SAP
Наименование ПО
SAP Notes (1630309-4) SAP Support Packages (746, SAPK-70012INWEBCUIF, SAPK-70109INWEBCUIF, SAPK-73004INWEBCUIF, SAPK-73102INWEBCUIF, SAPKA70027)
Описание
BSP Page/s within CRM-IC-FRW-UI does/do not sufficiently encode OUTPUT parameters, resulting in a cross-site scripting issue.Cross-site scripting can be used to steal another user's authentication  information, such as data relating to their current session. A malicious  user who gains access to this data may use it to impersonate the user  and access all information with the same rights as the target user.If an administrator is impersonated, the security of the application may be fully compromised.
Как исправить
Please apply this note or import the changes via the relevant support package.------------------------------------------------------------------------|Manual Pre-Implement.                                                 |------------------------------------------------------------------------|VALID FOR                                                             ||Software Component   WEBCUIF                                          || Release 700          SAPK-70001INWEBCUIF - SAPK-70011INWEBCUIF       || Release 701          SAPK-70103INWEBCUIF - SAPK-70108INWEBCUIF       || Release 731          SAPK-73101INWEBCUIF - SAPK-73101INWEBCUIF       || Release 730          Until SAPK-73003INWEBCUIF                       |------------------------------------------------------------------------Implement note 1628849 in advance.
Ссылки