Карточка уязвимости
Характеристики уязвимости
Уровень опасности
Оценка CVSS
Производитель ПО
Наименование ПО
SAP Notes
(1674219-1)
SAP Support Packages
(SAPKH60022, SAPKH60212, SAPKH60311, SAPKH60412, SAPKH60509, SAPKH60603)
Описание
Follwing ITS Services within Application Components CO-OM, CO-OM-CCA, FI-GL, and QM do not sufficiently encode OUTPUT parameters, resulting in a cross-site scripting issue:
SPS1D
SPS2D
SR63D
SRGEN
SR00
SRPH
SR_LIBRARY
SR61
SR62
SRK1
SRK2
SRK3
SOR1
SH01
SH02
SR01
SR12
SR12_START
SR31
SR71_ERP
SR41
SR42
Cross-site scripting can be used to steal another user's authentication information, such as data relating to their current session. A malicious user who gains access to this data may use it to impersonate the user and access all information with the same rights as the target user.
If an administrator is impersonated, the security of the application may be fully compromised.
SPS1D
SPS2D
SR63D
SRGEN
SR00
SRPH
SR_LIBRARY
SR61
SR62
SRK1
SRK2
SRK3
SOR1
SH01
SH02
SR01
SR12
SR12_START
SR31
SR71_ERP
SR41
SR42
Cross-site scripting can be used to steal another user's authentication information, such as data relating to their current session. A malicious user who gains access to this data may use it to impersonate the user and access all information with the same rights as the target user.
If an administrator is impersonated, the security of the application may be fully compromised.
Как исправить
Ссылки