Twenty Year Anniversary

SAP Enterprise Portal 7.50 Cross Site Scripting

SAP Enterprise Portal 7.50 Cross Site Scripting
Posted Sep 29, 2017
Authored by Imran Khan

SAP Enterprise Portal versions 7.50 and below suffer from a cross site scripting vulnerability.

tags | advisory, xss
advisories | CVE-2017-10701
MD5 | b7e533258b6fc2e9044b7988259677f3

SAP Enterprise Portal 7.50 Cross Site Scripting

Change Mirror Download
*SAP Enterprise Portal and Clients Input Validation Flaw Lets Remote Users
Conduct Cross-Site Scripting Attacks*


*CVE Reference:* CVE-2017-10701


*Date:* Sep 27 2017


*Severity Rating: CVSS v3 Base Score:* 6.1 (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I
:L/A:N)


*Fix Available:* Yes *Vendor Confirmed:* Yes


*Version(s):* SAP Enterprise Portal 7.50 and prior


*Description:* A vulnerability was reported in SAP Enterprise Portal (EP)
and Clients. A remote user can conduct cross-site scripting attacks.

The software does not properly filter HTML code from user-supplied input
before displaying the input. A remote user can cause arbitrary scripting
code to be executed by the target user's browser. The code will originate
from the site running the SAP Enterprise Portal (EP) and will run in the
security context of that site. As a result, the code will be able to access
the target user's cookies (including authentication cookies), if any,
associated with the site, access data recently submitted by the target user
via web form to the site, or take actions on the site acting as the target
user.


*Impact:* A remote user can access the target user's cookies (including
authentication cookies), if any, associated with the site running the SAP
Enterprise Portal, access data recently submitted by the target user via
web form to the site, or take actions on the site acting as the target user.


*Link to remedies:*

Web Dynpro Java - https://launchpad.support.sap.com/#/notes/2469860
SAPGUI for HTML- https://launchpad.support.sap.com/#/notes/2471209
Web Dynpro ABAP -https://launchpad.support.sap.com/#/notes/2488516

*Credits:* Imran Khan @Netizen01k reported this vulnerability.


Comments

RSS Feed Subscribe to this comment feed

No comments yet, be the first!

Login or Register to post a comment

Want To Donate?


Bitcoin: 18PFeCVLwpmaBuQqd5xAYZ8bZdvbyEWMmU

File Archive:

July 2018

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jul 1st
    1 Files
  • 2
    Jul 2nd
    26 Files
  • 3
    Jul 3rd
    15 Files
  • 4
    Jul 4th
    11 Files
  • 5
    Jul 5th
    13 Files
  • 6
    Jul 6th
    4 Files
  • 7
    Jul 7th
    4 Files
  • 8
    Jul 8th
    1 Files
  • 9
    Jul 9th
    16 Files
  • 10
    Jul 10th
    15 Files
  • 11
    Jul 11th
    32 Files
  • 12
    Jul 12th
    22 Files
  • 13
    Jul 13th
    15 Files
  • 14
    Jul 14th
    1 Files
  • 15
    Jul 15th
    1 Files
  • 16
    Jul 16th
    21 Files
  • 17
    Jul 17th
    15 Files
  • 18
    Jul 18th
    15 Files
  • 19
    Jul 19th
    17 Files
  • 20
    Jul 20th
    0 Files
  • 21
    Jul 21st
    0 Files
  • 22
    Jul 22nd
    0 Files
  • 23
    Jul 23rd
    0 Files
  • 24
    Jul 24th
    0 Files
  • 25
    Jul 25th
    0 Files
  • 26
    Jul 26th
    0 Files
  • 27
    Jul 27th
    0 Files
  • 28
    Jul 28th
    0 Files
  • 29
    Jul 29th
    0 Files
  • 30
    Jul 30th
    0 Files
  • 31
    Jul 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2018 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close