Карточка уязвимости
Характеристики уязвимости
Уровень опасности
Оценка CVSS
Производитель ПО
Наименование ПО
SAP Notes
(1472395-6)
SAP Support Packages
(SAPK-60018ININSURANC, SAPK-60208ININSURANC, SAPK-60307ININSURANC, SAPK-60407ININSURANC, SAPK-60502ININSURANC, SAPKIPIN19)
Описание
Since there is no sufficient input validation using the component FSCDITAGCY_START, a permanent cross-site scripting may be triggered. As a result, an attacker can store manipulated content on a server. This content is displayed automatically for a victim and is interpreted by the victim's browser. This enables the attacker to obtain the information of a user. The attacker can use this information so that the application assumes that the attacker has the relevant authorization. As a result, the attacker can use the application with the authorizations of the victim. If a user with administration authorizations falls victim to an attack, all of the data of the application may be compromised.
Как исправить
Implement this note or import the relevant Support Package. In addition, implement Note 1480715.
Ссылки