• Все разделы
  • Статьи
  • Медиа
  • Новости
  • Нормативные материалы
  • Конференции
  • Глоссарий

Note 1690738 - Unauthoried modification in BSP application in CRM-ISP-BTX

Главная Специалистам База уязвимостей Note 1690738 - Unauthoried modification in BSP application in CRM-ISP-BTX

Карточка уязвимости

Характеристики уязвимости

Уровень опасности
Оценка CVSS
Производитель ПО
SAP
Наименование ПО
SAP Notes (1690738-1) SAP Support Packages (712, SAPKU52011, SAPKU60012, SAPKU70012, SAPKU70109, SAPKU70204)
Описание
BSP Pages: session_buffered_frame.htm and session_single_frame.htm (from  BSP application CRMCMP_GRM_GPM) within CRM-IPS-BTX does not sufficiently  encode OUTPUT parameters, resulting in a cross site scripting issue.

Cross-site scripting can be used to steal another user's authentication information, such as data relating to their current session. A malicious  user who gains access to this data may use it to impersonate the user  and access all information with the same rights as the target user.

If an administrator is impersonated, the security of the application may be fully compromised.
Как исправить
Please apply this note or import the changes via the relevant support
package.
Ссылки