• Все разделы
  • Статьи
  • Медиа
  • Новости
  • Нормативные материалы
  • Конференции
  • Глоссарий

Не установлено обновление Note 1458924

Главная Специалистам База уязвимостей Не установлено обновление Note 1458924

Карточка уязвимости

Характеристики уязвимости

Уровень опасности
Оценка CVSS
Производитель ПО
SAP
Наименование ПО
SAP Notes (1458924-2) SAP Support Packages (SAPKB62069, SAPKB64027, SAPKB70022, SAPKB70107, SAPKB70205, SAPKB71011, SAPKB71106, SAPKB72004)
Описание
The SXSL_DEMO and SXSLT_TRAINING packages contain old demo content  related to the ABAP XSLT processor. This includes BSP applications which  would read information from URL parameters. The content was delivered as  part of software component BC-ABA-XML. It is no longer up to date, and  its removal will not affect productive software components.
Stored cross-site scripting can be used to permanently modify displayed  content from a web site, allowing the malicious user to embed content  that is rendered automatically, without the need to individually target victims.
Stored cross-site scripting can also be used to steal another user#s  authentication information, such as data relating to their current session.
An attacker who gains access to this data could use it to impersonate  the user and access all information with the same rights as the target  user. If an administrator is impersonated, the application#s security could be fully compromised.
Как исправить
Apply the support package given in this SAP note.
Individual corrective instructions are not provided due to their complexity. Anyhow, you may decide to remove the complete packages SXSLT_DEMO and SXSLT_TRAINING in your system by modification.
Ссылки