Exploit the possiblities

SAP Enterprise Portal 7.50 Cross Site Scripting

SAP Enterprise Portal 7.50 Cross Site Scripting
Posted Sep 29, 2017
Authored by Imran Khan

SAP Enterprise Portal versions 7.50 and below suffer from a cross site scripting vulnerability.

tags | advisory, xss
advisories | CVE-2017-10701
MD5 | b7e533258b6fc2e9044b7988259677f3

SAP Enterprise Portal 7.50 Cross Site Scripting

Change Mirror Download
*SAP Enterprise Portal and Clients Input Validation Flaw Lets Remote Users
Conduct Cross-Site Scripting Attacks*


*CVE Reference:* CVE-2017-10701


*Date:* Sep 27 2017


*Severity Rating: CVSS v3 Base Score:* 6.1 (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I
:L/A:N)


*Fix Available:* Yes *Vendor Confirmed:* Yes


*Version(s):* SAP Enterprise Portal 7.50 and prior


*Description:* A vulnerability was reported in SAP Enterprise Portal (EP)
and Clients. A remote user can conduct cross-site scripting attacks.

The software does not properly filter HTML code from user-supplied input
before displaying the input. A remote user can cause arbitrary scripting
code to be executed by the target user's browser. The code will originate
from the site running the SAP Enterprise Portal (EP) and will run in the
security context of that site. As a result, the code will be able to access
the target user's cookies (including authentication cookies), if any,
associated with the site, access data recently submitted by the target user
via web form to the site, or take actions on the site acting as the target
user.


*Impact:* A remote user can access the target user's cookies (including
authentication cookies), if any, associated with the site running the SAP
Enterprise Portal, access data recently submitted by the target user via
web form to the site, or take actions on the site acting as the target user.


*Link to remedies:*

Web Dynpro Java - https://launchpad.support.sap.com/#/notes/2469860
SAPGUI for HTML- https://launchpad.support.sap.com/#/notes/2471209
Web Dynpro ABAP -https://launchpad.support.sap.com/#/notes/2488516

*Credits:* Imran Khan @Netizen01k reported this vulnerability.


Comments

RSS Feed Subscribe to this comment feed

No comments yet, be the first!

Login or Register to post a comment

Want To Donate?


Bitcoin: 18PFeCVLwpmaBuQqd5xAYZ8bZdvbyEWMmU

File Archive:

February 2018

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Feb 1st
    15 Files
  • 2
    Feb 2nd
    15 Files
  • 3
    Feb 3rd
    15 Files
  • 4
    Feb 4th
    13 Files
  • 5
    Feb 5th
    16 Files
  • 6
    Feb 6th
    15 Files
  • 7
    Feb 7th
    15 Files
  • 8
    Feb 8th
    15 Files
  • 9
    Feb 9th
    18 Files
  • 10
    Feb 10th
    8 Files
  • 11
    Feb 11th
    8 Files
  • 12
    Feb 12th
    17 Files
  • 13
    Feb 13th
    15 Files
  • 14
    Feb 14th
    15 Files
  • 15
    Feb 15th
    17 Files
  • 16
    Feb 16th
    18 Files
  • 17
    Feb 17th
    37 Files
  • 18
    Feb 18th
    2 Files
  • 19
    Feb 19th
    16 Files
  • 20
    Feb 20th
    16 Files
  • 21
    Feb 21st
    15 Files
  • 22
    Feb 22nd
    16 Files
  • 23
    Feb 23rd
    31 Files
  • 24
    Feb 24th
    0 Files
  • 25
    Feb 25th
    0 Files
  • 26
    Feb 26th
    0 Files
  • 27
    Feb 27th
    0 Files
  • 28
    Feb 28th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2018 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close