ID

VAR-201109-0421


TITLE

SAP Web Application Server WEBRFC ICF Service Cross-Site Scripting Vulnerability

Trust: 0.3

sources: BID: 49646

DESCRIPTION

SAP Web Application Server is prone to a cross-site scripting vulnerability because the application fails to sufficiently sanitize user-supplied input. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and to launch other attacks. SAP Web Application Server 7.0 is vulnerable; other versions may also be affected.

Trust: 0.3

sources: BID: 49646

AFFECTED PRODUCTS

vendor:sapmodel:web application serverscope:eqversion:7.0

Trust: 0.3

sources: BID: 49646

THREAT TYPE

network

Trust: 0.3

sources: BID: 49646

TYPE

Input Validation Error

Trust: 0.3

sources: BID: 49646

EXTERNAL IDS

db:BIDid:49646

Trust: 0.3

sources: BID: 49646

REFERENCES

url:http://seclists.org/fulldisclosure/2011/sep/130

Trust: 0.3

url:http://www.sap.com/

Trust: 0.3

url:/archive/1/519649

Trust: 0.3

sources: BID: 49646

CREDITS

Mariano Nuñez Di Croce

Trust: 0.3

sources: BID: 49646

SOURCES

db:BIDid:49646

LAST UPDATE DATE

2022-05-17T02:10:46.875000+00:00


SOURCES UPDATE DATE

db:BIDid:49646date:2011-09-14T00:00:00

SOURCES RELEASE DATE

db:BIDid:49646date:2011-09-14T00:00:00