• Все разделы
  • Статьи
  • Медиа
  • Новости
  • Нормативные материалы
  • Конференции
  • Глоссарий

Не установлено обновление Note 1441953

Главная Специалистам База уязвимостей Не установлено обновление Note 1441953

Карточка уязвимости

Характеристики уязвимости

Уровень опасности
Оценка CVSS
Производитель ПО
SAP
Наименование ПО
SAP Notes (1441953-1) SAP Support Packages (SAPKB70107, SAPKB70204, SAPKB71105, SAPKB72003)
Описание
Certain Web Dynpro ABAP pages do not encode the input parameters  sufficiently. This causes a reflexive cross-site scripting (XSS) problem. XSS can be used to steal the logon data of another user.
Reflexive: This gap can be used to deface or change the contents of a  page (for example).
An attacker that has obtained this data can use this data to imitate a  different user in the system; the attacker then has access to all of  this user's information and has the same authorizations as this user.
If the user is an administration user, the security of the entire  application may be compromised.
Как исправить
Implement the correction instructions or import the relevant Support Package.
Ссылки