Карточка уязвимости
Характеристики уязвимости
Уровень опасности
Оценка CVSS
Производитель ПО
Наименование ПО
SAP Notes
(1468513-28)
SAP Support Packages
(SAPKA62069, SAPKA62070, SAPKA64027, SAPKA64028, SAPKA70023, SAPKA70024, SAPKA70107, SAPKA70108, SAPKA70109, SAPKA70205, SAPKA70206, SAPKA70207, SAPKA71011, SAPKA71012, SAPKA71106, SAPKA71107, SAPKA73002)
Описание
1. A Web Survey executes functions by calling certain URLs with parameters. If an attacker succeeds in getting the browser of a logged on user to execute arbitrary inquiries, the attacker can call functions in the Web Survey with the rights of the user. To do so, an attacker can exploit a cross-site scripting vulnerability or introduce a special link to the user in the form of an e-mail, for example.
2. Since there is no sufficient input validation by BSP in Web Survey, this results in a reflected cross-site scripting issue. A reflected cross-site scripting attack can be used to non-permanently deface or modify displayed content from a web site. Reflected cross-site scripting can be used to steal another user#s authentication information, such as data relating to their current session. An attacker who gains access to this data could use it to impersonate the user and access all information with the same rights as the target user. If an administrator is impersonated, the application#s security could be fully compromised.
2. Since there is no sufficient input validation by BSP in Web Survey, this results in a reflected cross-site scripting issue. A reflected cross-site scripting attack can be used to non-permanently deface or modify displayed content from a web site. Reflected cross-site scripting can be used to steal another user#s authentication information, such as data relating to their current session. An attacker who gains access to this data could use it to impersonate the user and access all information with the same rights as the target user. If an administrator is impersonated, the application#s security could be fully compromised.
Как исправить
1. For more information and instructions, see Note 1520324. Before you implement this note, you must implement the corrections contained in Note 1520324 in your system.
2. Implement the attached correction instructions that correspond to your release. As a result, the report BSP_XSRF_PARAM_UWS_FORM is also created in your system.
3. Execute the report BSP_XSRF_PARAM_UWS_FORM and when requested, specify a relevant transport request number. The report fills the database table BSPTEMPXSRFSTORE with the relevant table entries for BSP applications that are adjusted by this note.
2. Implement the attached correction instructions that correspond to your release. As a result, the report BSP_XSRF_PARAM_UWS_FORM is also created in your system.
3. Execute the report BSP_XSRF_PARAM_UWS_FORM and when requested, specify a relevant transport request number. The report fills the database table BSPTEMPXSRFSTORE with the relevant table entries for BSP applications that are adjusted by this note.
Ссылки