Карточка уязвимости
Характеристики уязвимости
Уровень опасности
Оценка CVSS
Производитель ПО
Наименование ПО
SAP Notes
(1507377-1)
SAP Support Packages
(SAPK-70204INSAPBSFND)
Описание
DocumentBuilder executes certain functions through referencing specific URLs. When an attacker tricks an authenticated user#s browser into making a request containing a certain URL and specific parameters, the function is executed with the rights of the user.
If present, the attacker may use a Cross Site Scripting attack to trigger the exploit, or use an approach in which a link to click is presented to the victim.
If present, the attacker may use a Cross Site Scripting attack to trigger the exploit, or use an approach in which a link to click is presented to the victim.
Как исправить
Apply Support Package and/or attached correction.
------------------------------------------------------------------------
|Manual Post-Implement. |
------------------------------------------------------------------------
|VALID FOR |
|Software Component SAP_BS_FND |
| Release 702 Until SAPK-70203INSAPBSFND |
------------------------------------------------------------------------
Goto transaction SE80 (repository browser) and pick the 'BSP Application' option form the drop down list. Enter /IPRO/EDITOR for the object and then go to the properties of the application. Change to edit mode and check mark the flag for XSRF protection. Save and activate the change.
Do the same for application /IPRO/EDITOR.
------------------------------------------------------------------------
|Manual Post-Implement. |
------------------------------------------------------------------------
|VALID FOR |
|Software Component SAP_BS_FND |
| Release 702 Until SAPK-70203INSAPBSFND |
------------------------------------------------------------------------
Goto transaction SE80 (repository browser) and pick the 'BSP Application' option form the drop down list. Enter /IPRO/EDITOR for the object and then go to the properties of the application. Change to edit mode and check mark the flag for XSRF protection. Save and activate the change.
Do the same for application /IPRO/EDITOR.
Ссылки