• Все разделы
  • Статьи
  • Медиа
  • Новости
  • Нормативные материалы
  • Конференции
  • Глоссарий

Note 1674219 - Unauthorized modification in ITS-Services of ISR

Главная Специалистам База уязвимостей Note 1674219 - Unauthorized modification in ITS-Services of ISR

Карточка уязвимости

Характеристики уязвимости

Уровень опасности
Оценка CVSS
Производитель ПО
SAP
Наименование ПО
SAP Notes (1674219-1) SAP Support Packages (SAPKH60022, SAPKH60212, SAPKH60311, SAPKH60412, SAPKH60509, SAPKH60603)
Описание
Follwing ITS Services within Application Components CO-OM, CO-OM-CCA,  FI-GL, and QM do not sufficiently encode OUTPUT parameters, resulting in a cross-site scripting issue:
SPS1D
SPS2D
SR63D
SRGEN
SR00
SRPH
SR_LIBRARY
SR61
SR62
SRK1
SRK2
SRK3
SOR1
SH01
SH02
SR01
SR12
SR12_START
SR31
SR71_ERP
SR41
SR42
Cross-site scripting can be used to steal another user's authentication  information, such as data relating to their current session. A malicious  user who gains access to this data may use it to impersonate the user  and access all information with the same rights as the target user.

If an administrator is impersonated, the security of the application may be fully compromised.
Как исправить
Ссылки