Карточка уязвимости
Характеристики уязвимости
Уровень опасности
Оценка CVSS
Производитель ПО
Наименование ПО
SAP Notes
(1477597-5)
SAP Support Packages
(CM+COLLABORATION_60_640_SP023_000004, CM+COLLABORATION_60_640_SP024_000004, CM+COLLABORATION_60_640_SP025_000004, CM+COLLABORATION_60_640_SP026_000003, CM+COLLABORATION_60_640_SP027_000000, CM+COLLABORATION_60_640_SP999999_999999, KMC_CONTENT_MANAGEMENT_700_SP019_000004, KMC_CONTENT_MANAGEMENT_700_SP020_000003, KMC_CONTENT_MANAGEMENT_700_SP021_000002, KMC_CONTENT_MANAGEMENT_700_SP022_000001, KMC_CONTENT_MANAGEMENT_700_SP023_000000, KMC_CONTENT_MANAGEMENT_700_SP999999_999999, KMC_CONTENT_MANAGEMENT_701_SP004_000001, KMC_CONTENT_MANAGEMENT_701_SP005_000002, KMC_CONTENT_MANAGEMENT_701_SP006_000002, KMC_CONTENT_MANAGEMENT_701_SP007_000001, KMC_CONTENT_MANAGEMENT_701_SP008_000000, KMC_CONTENT_MANAGEMENT_701_SP999999_999999, KMC_CONTENT_MANAGEMENT_702_SP003_000001, KMC_CONTENT_MANAGEMENT_702_SP004_000001, KMC_CONTENT_MANAGEMENT_702_SP005_000000, KMC_CONTENT_MANAGEMENT_702_SP999999_999999, KMC_CONTENT_MANAGEMENT_730_SP001_000000, KMC_CONTENT_MANAGEMENT_730_SP999999_999999)
Описание
Pages resulting in a stored cross site scripting issue.
It can be used to permanently modify displayed content from a web site, allowing the malicious user to embed content that is rendered automatically, without the need to individually target victims.
Stored cross site scripting can also be used to steal another user#s authentication information such as data relating to their current session.
An attacker who gains access to this data may use this to impersonate the user and access all information with the same rights as the target user. In case of an administrator being imperso-nated, a full compromise of the application#s security can be may occur.
It can be used to permanently modify displayed content from a web site, allowing the malicious user to embed content that is rendered automatically, without the need to individually target victims.
Stored cross site scripting can also be used to steal another user#s authentication information such as data relating to their current session.
An attacker who gains access to this data may use this to impersonate the user and access all information with the same rights as the target user. In case of an administrator being imperso-nated, a full compromise of the application#s security can be may occur.
Как исправить
A.) The issue is cleared in these deliveries:
Patch 4 for KMC CONTENT MANAGEMENT 6.40 SP 23
Patch 1 for KMC CONTENT MANAGEMENT 6.40 SP 24
Patch 1 for KMC CONTENT MANAGEMENT 6.40 SP 25
Patch 1 for KMC CONTENT MANAGEMENT 6.40 SP 26
Patch 4 for KMC CONTENT MANAGEMENT 7.00 SP 19
Patch 3 for KMC CONTENT MANAGEMENT 7.00 SP 20
Patch 2 for KMC CONTENT MANAGEMENT 7.00 SP 21
Patch 1 for KMC CONTENT MANAGEMENT 7.00 SP 22
Patch 1 for SAP EHP1 FOR SAP NETWEAVER 7.0 SP4
Patch 2 for SAP EHP1 FOR SAP NETWEAVER 7.0 SP5
Patch 2 for SAP EHP1 FOR SAP NETWEAVER 7.0 SP6
SAP EHP1 FOR SAP NETWEAVER 7.0 SP7
SAP EHP1 FOR SAP NETWEAVER 7.0 SP8
Patch 1 for SAP EHP2 FOR SAP NETWEAVER 7.0 SP3
Patch 1 for SAP EHP2 FOR SAP NETWEAVER 7.0 SP4
SAP EHP2 FOR SAP NETWEAVER 7.0 SP5
SAP NETWEAVER 7.30 SP1
See http://service.sap.com/sp-stacks -> SP Stack Schedule for schedule details and updates.
B.) Possible workaround before the release of mentioned deliveries:
none
Patch 4 for KMC CONTENT MANAGEMENT 6.40 SP 23
Patch 1 for KMC CONTENT MANAGEMENT 6.40 SP 24
Patch 1 for KMC CONTENT MANAGEMENT 6.40 SP 25
Patch 1 for KMC CONTENT MANAGEMENT 6.40 SP 26
Patch 4 for KMC CONTENT MANAGEMENT 7.00 SP 19
Patch 3 for KMC CONTENT MANAGEMENT 7.00 SP 20
Patch 2 for KMC CONTENT MANAGEMENT 7.00 SP 21
Patch 1 for KMC CONTENT MANAGEMENT 7.00 SP 22
Patch 1 for SAP EHP1 FOR SAP NETWEAVER 7.0 SP4
Patch 2 for SAP EHP1 FOR SAP NETWEAVER 7.0 SP5
Patch 2 for SAP EHP1 FOR SAP NETWEAVER 7.0 SP6
SAP EHP1 FOR SAP NETWEAVER 7.0 SP7
SAP EHP1 FOR SAP NETWEAVER 7.0 SP8
Patch 1 for SAP EHP2 FOR SAP NETWEAVER 7.0 SP3
Patch 1 for SAP EHP2 FOR SAP NETWEAVER 7.0 SP4
SAP EHP2 FOR SAP NETWEAVER 7.0 SP5
SAP NETWEAVER 7.30 SP1
See http://service.sap.com/sp-stacks -> SP Stack Schedule for schedule details and updates.
B.) Possible workaround before the release of mentioned deliveries:
none
Ссылки