Карточка уязвимости
Характеристики уязвимости
Уровень опасности
Оценка CVSS
Производитель ПО
Наименование ПО
SAP Notes
(1441953-1)
SAP Support Packages
(SAPKB70107, SAPKB70204, SAPKB71105, SAPKB72003)
Описание
Certain Web Dynpro ABAP pages do not encode the input parameters sufficiently. This causes a reflexive cross-site scripting (XSS) problem. XSS can be used to steal the logon data of another user.
Reflexive: This gap can be used to deface or change the contents of a page (for example).
An attacker that has obtained this data can use this data to imitate a different user in the system; the attacker then has access to all of this user's information and has the same authorizations as this user.
If the user is an administration user, the security of the entire application may be compromised.
Reflexive: This gap can be used to deface or change the contents of a page (for example).
An attacker that has obtained this data can use this data to imitate a different user in the system; the attacker then has access to all of this user's information and has the same authorizations as this user.
If the user is an administration user, the security of the entire application may be compromised.
Как исправить
Implement the correction instructions or import the relevant Support Package.
Ссылки