• Все разделы
  • Статьи
  • Медиа
  • Новости
  • Нормативные материалы
  • Конференции
  • Глоссарий

Не установлено обновление Note 1472395

Главная Специалистам База уязвимостей Не установлено обновление Note 1472395

Карточка уязвимости

Характеристики уязвимости

Уровень опасности
Оценка CVSS
Производитель ПО
SAP
Наименование ПО
SAP Notes (1472395-6) SAP Support Packages (SAPK-60018ININSURANC, SAPK-60208ININSURANC, SAPK-60307ININSURANC, SAPK-60407ININSURANC, SAPK-60502ININSURANC, SAPKIPIN19)
Описание
Since there is no sufficient input validation using the component  FSCDITAGCY_START, a permanent cross-site scripting may be triggered. As  a result, an attacker can store manipulated content on a server. This  content is displayed automatically for a victim and is interpreted by  the victim's browser. This enables the attacker to obtain the  information of a user. The attacker can use this information so that the  application assumes that the attacker has the relevant authorization. As  a result, the attacker can use the application with the authorizations  of the victim. If a user with administration authorizations falls victim  to an attack, all of the data of the application may be compromised.
Как исправить
Implement this note or import the relevant Support Package. In addition, implement Note 1480715.
Ссылки