Карточка уязвимости
Характеристики уязвимости
Уровень опасности
Оценка CVSS
Производитель ПО
Наименование ПО
SAP Notes
(1518807-2)
SAP Support Packages
(SAPK-60209INEARETAIL, SAPK-60308INEARETAIL, SAPK-60409INEARETAIL, SAPK-60503INEARETAIL, SAPK-60504INEARETAIL, SAPKGPRC25, SAPKGPRD19)
Описание
WEB_PRICAT executes certain functions by referencing specific URLs with parameters. When a malicious user tricks an authenticated user#s browser into making a request, the functions in WEB_PRICAT are executed with the rights of the authenticated user. The malicious user may exploit a cross-site scripting vulnerability to do this, or they may present a special link to the victim, in the form of an email, for example.
Как исправить
Implement the correction instructions or import the specified Support Package.
Note the following:
1. For additional information and instructions, see Note 1481392. The corrections from Note 1481392 are a prerequisite for implementing this note.
2. Implement the correction instructions provided in this note.
These create the report ITS_XSRF_PARAM_WEB_PRICAT.
3. Execute the report ITS_XSRF_PARAM_WEB_PRICAT and when requested, specify a relevant transport request number. The report will add service parameters for the service WEB_PRICAT (maintained using the GUI configuration pushbutton for a service within transaction SICF).
Note the following:
1. For additional information and instructions, see Note 1481392. The corrections from Note 1481392 are a prerequisite for implementing this note.
2. Implement the correction instructions provided in this note.
These create the report ITS_XSRF_PARAM_WEB_PRICAT.
3. Execute the report ITS_XSRF_PARAM_WEB_PRICAT and when requested, specify a relevant transport request number. The report will add service parameters for the service WEB_PRICAT (maintained using the GUI configuration pushbutton for a service within transaction SICF).
Ссылки