ID

VAR-201007-0345


TITLE

SAP J2EE Engine Remote Cross-Site Scripting Vulnerability

Trust: 0.8

sources: IVD: 646bef30-1fb3-11e6-abef-000c29c66e3d // CNVD: CNVD-2010-1398

DESCRIPTION

The SAP J2EE engine is a core component of the SAP NetWeaver application platform, allowing Java solutions to be developed and executed within SAP. The J2EE engine includes a Web Services Navigator interface that allows remote attackers to perform cross-site scripting attacks by submitting malicious parameters to the interface. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site and to steal cookie-based authentication credentials

Trust: 0.99

sources: CNVD: CNVD-2010-1398 // BID: 41805 // IVD: 646bef30-1fb3-11e6-abef-000c29c66e3d

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.8

sources: IVD: 646bef30-1fb3-11e6-abef-000c29c66e3d // CNVD: CNVD-2010-1398

AFFECTED PRODUCTS

vendor:sapmodel:j2ee engine corescope:eqversion:7.00

Trust: 1.1

vendor:sapmodel:j2ee engine corescope:eqversion:6.40

Trust: 0.9

vendor:sapmodel:j2ee engine corescope:eqversion:6.40*

Trust: 0.2

sources: IVD: 646bef30-1fb3-11e6-abef-000c29c66e3d // CNVD: CNVD-2010-1398 // BID: 41805

CVSS

SEVERITY

CVSSV2

CVSSV3

IVD: 646bef30-1fb3-11e6-abef-000c29c66e3d
value: LOW

Trust: 0.2

IVD: 646bef30-1fb3-11e6-abef-000c29c66e3d
severity: NONE
baseScore: NONE
vectorString: NONE
accessVector: NONE
accessComplexity: NONE
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: UNKNOWN

Trust: 0.2

sources: IVD: 646bef30-1fb3-11e6-abef-000c29c66e3d

THREAT TYPE

network

Trust: 0.3

sources: BID: 41805

TYPE

Input Validation Error

Trust: 0.3

sources: BID: 41805

PATCH

title:Patch for SAP J2EE Engine Core Unknown Cross-Site Scripting Vulnerabilityurl:https://www.cnvd.org.cn/patchinfo/show/667

Trust: 0.6

sources: CNVD: CNVD-2010-1398

EXTERNAL IDS

db:BIDid:41805

Trust: 0.9

db:CNVDid:CNVD-2010-1398

Trust: 0.8

db:IVDid:646BEF30-1FB3-11E6-ABEF-000C29C66E3D

Trust: 0.2

sources: IVD: 646bef30-1fb3-11e6-abef-000c29c66e3d // CNVD: CNVD-2010-1398 // BID: 41805

REFERENCES

url:http://seclists.org/fulldisclosure/2010/jul/287

Trust: 0.9

url:http://www.sap.com

Trust: 0.3

sources: CNVD: CNVD-2010-1398 // BID: 41805

CREDITS

Mariano Nunez Di Croce

Trust: 0.3

sources: BID: 41805

SOURCES

db:IVDid:646bef30-1fb3-11e6-abef-000c29c66e3d
db:CNVDid:CNVD-2010-1398
db:BIDid:41805

LAST UPDATE DATE

2022-05-17T02:08:20.890000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2010-1398date:2010-07-21T00:00:00
db:BIDid:41805date:2010-07-20T00:00:00

SOURCES RELEASE DATE

db:IVDid:646bef30-1fb3-11e6-abef-000c29c66e3ddate:2010-07-21T00:00:00
db:CNVDid:CNVD-2010-1398date:2010-07-21T00:00:00
db:BIDid:41805date:2010-07-20T00:00:00