• Все разделы
  • Статьи
  • Медиа
  • Новости
  • Нормативные материалы
  • Конференции
  • Глоссарий

Note 1555906 - Unauthorized modification of displayed content in HTMLB

Главная Специалистам База уязвимостей Note 1555906 - Unauthorized modification of displayed content in HTMLB

Карточка уязвимости

Характеристики уязвимости

Уровень опасности
Оценка CVSS
Производитель ПО
SAP
Наименование ПО
SAP Notes (1555906-5) SAP Support Packages (CM+COLLABORATION_60_640_SP027_000001, CM+COLLABORATION_60_640_SP028_000000, CM+COLLABORATION_60_640_SP999999_999999, JAVA_FRAMEWORK_OFFLINE_711_SP006_000008, JAVA_FRAMEWORK_OFFLINE_711_SP007_000000, JAVA_FRAMEWORK_OFFLINE_711_SP999999_999999, JAVA_FRAMEWORK_OFFLINE_720_SP004_000003, JAVA_FRAMEWORK_OFFLINE_720_SP005_000000, JAVA_FRAMEWORK_OFFLINE_720_SP999999_999999, PORTAL_FRAMEWORK_700_SP021_000013, PORTAL_FRAMEWORK_700_SP022_000008, PORTAL_FRAMEWORK_700_SP023_000003, PORTAL_FRAMEWORK_700_SP024_000000, PORTAL_FRAMEWORK_700_SP999999_999999, PORTAL_FRAMEWORK_701_SP008_000002, PORTAL_FRAMEWORK_701_SP009_000000, PORTAL_FRAMEWORK_701_SP999999_999999, PORTAL_FRAMEWORK_702_SP007_000000, PORTAL_FRAMEWORK_702_SP008_000000, PORTAL_FRAMEWORK_702_SP999999_999999, SAP_JAVA_TECH_SERVICES_700_SP021_000024, SAP_JAVA_TECH_SERVICES_700_SP022_000015, SAP_JAVA_TECH_SERVICES_700_SP023_000002, SAP_JAVA_TECH_SERVICES_700_SP024_000000, SAP_JAVA_TECH_SERVICES_700_SP999999_999999, SAP_JAVA_TECH_SERVICES_701_SP008_000001, SAP_JAVA_TECH_SERVICES_701_SP009_000000, SAP_JAVA_TECH_SERVICES_701_SP999999_999999, SAP_JAVA_TECH_SERVICES_702_SP007_000000, SAP_JAVA_TECH_SERVICES_702_SP008_000000, SAP_JAVA_TECH_SERVICES_702_SP999999_999999)
Описание
HTMLB do not sufficiently encode input or output parameters, resulting  in a reflected cross-site scripting issue. Reflected cross-site scripting attack can be used to non-permanently deface or modify  displayed content from a Web site. Reflected cross-site scripting can be  used to steal another user#s authentication information, such as data  relating to their current session. An attacker who gains access to this  data may use it to impersonate the user and access all information with  the same rights as the target user. If an administrator is impersonated,  the security of the application may be fully compromised.
Как исправить
The issue described above will be fixed by an HTMLB for Java patch. In section "SP Patch Level" you can find information which patches contain the respective correction.

Downloading HTMLB for Java Patches:
----------------------------------
All HTMLB for Java patches are available on SAP Service Marketplace. Note 330793 explains how to download patches from SAP Service Marketplace.

Release Specific Details:
------------------------
NW04S/ NW 7.00 / NW04S Ehp1/ NW 7.01/ NW04S Ehp2 / NW 7.02:
----------------------------------------------------------
The patch for this release will be a SCA. Deploy the SCA directly using SDM.

Recommendation for Portal Usage:
In the "SP Patch Level" tab, if there is no software component for EPBC2, then please apply the latest relevant EPBC2. SCA which is available in the service market place.

Recommendation for Portal Independent Usage:
In the "SP Patch Level" tab, if there is no software component for SAPJTECHS, then please apply the latest relevant SAPJTECHS.SCA which is available in the service market place.

NW07 / NW 7.10 / NW07 Ehp1 / NW 7.11:
------------------------------------
The patch for this release will be a SCA. Deploy the SCA directly using SDM.

Recommendation for Portal Usage:
In the "SP Patch Level" tab, if there is no software component for EPBASIS, then please apply the latest relevant EPBASIS.SCA which is available in the service market place.

Recommendation for Portal Independent Usage:
In the "SP Patch Level" tab, if there is no software component for FRAMEWORK, then please apply the latest relevant FRAMEWORK.SCA which is available in the service market place. Note: Due to the fact that many of the SDAs included in the SCA  are offine deployment, the engine is restarted during the deployment. An update is only required on the engine. Time required: The required time depends on whether the engine has to be restarted. In addition, the time required for the restart is determined by the applications installed on the engine.
Ссылки