ID

VAR-201007-0346


TITLE

SAP Netweaver 'wsnavigator' Cross-Site Scripting Vulnerability

Trust: 0.8

sources: IVD: 0e46d7f0-1fb3-11e6-abef-000c29c66e3d // CNVD: CNVD-2010-1420

DESCRIPTION

SAP NetWeaver is the technical foundation for SAP Business Suite solutions, SAP xApps composite applications, partner solutions, and custom applications. The SAP NetWeaver wsnavigator component has a cross-site scripting attack that allows an attacker to exploit a vulnerability to gain sensitive information or hijack a target user session. SAP Netweaver is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks. SAP Netweaver 6.4 through 7.0 is vulnerable; other versions may also be affected

Trust: 0.99

sources: CNVD: CNVD-2010-1420 // BID: 41925 // IVD: 0e46d7f0-1fb3-11e6-abef-000c29c66e3d

IOT TAXONOMY

category:['ICS', 'Network device']sub_category: -

Trust: 0.6

category:['ICS']sub_category: -

Trust: 0.2

sources: IVD: 0e46d7f0-1fb3-11e6-abef-000c29c66e3d // CNVD: CNVD-2010-1420

AFFECTED PRODUCTS

vendor:sapmodel:netweaverscope:eqversion:7.0

Trust: 1.1

vendor:sapmodel:netweaverscope:eqversion:6.4

Trust: 0.9

vendor:sapmodel:netweaverscope:eqversion:6.4*

Trust: 0.2

sources: IVD: 0e46d7f0-1fb3-11e6-abef-000c29c66e3d // CNVD: CNVD-2010-1420 // BID: 41925

CVSS

SEVERITY

CVSSV2

CVSSV3

IVD: 0e46d7f0-1fb3-11e6-abef-000c29c66e3d
value: LOW

Trust: 0.2

IVD: 0e46d7f0-1fb3-11e6-abef-000c29c66e3d
severity: NONE
baseScore: NONE
vectorString: NONE
accessVector: NONE
accessComplexity: NONE
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: UNKNOWN

Trust: 0.2

sources: IVD: 0e46d7f0-1fb3-11e6-abef-000c29c66e3d

THREAT TYPE

network

Trust: 0.3

sources: BID: 41925

TYPE

Input Validation Error

Trust: 0.3

sources: BID: 41925

PATCH

title:Patch for SAP Netweaver 'wsnavigator' Cross-Site Scripting Vulnerabilityurl:https://www.cnvd.org.cn/patchinfo/show/698

Trust: 0.6

sources: CNVD: CNVD-2010-1420

EXTERNAL IDS

db:BIDid:41925

Trust: 0.9

db:CNVDid:CNVD-2010-1420

Trust: 0.8

db:IVDid:0E46D7F0-1FB3-11E6-ABEF-000C29C66E3D

Trust: 0.2

sources: IVD: 0e46d7f0-1fb3-11e6-abef-000c29c66e3d // CNVD: CNVD-2010-1420 // BID: 41925

REFERENCES

url:http://dsecrg.com/pages/vul/show.php?id=140

Trust: 0.9

url:http://www.sap.com/platform/netweaver/index.epx

Trust: 0.3

url:/archive/1/512584

Trust: 0.3

sources: CNVD: CNVD-2010-1420 // BID: 41925

CREDITS

Alexandr Polyakov

Trust: 0.3

sources: BID: 41925

SOURCES

db:IVDid:0e46d7f0-1fb3-11e6-abef-000c29c66e3d
db:CNVDid:CNVD-2010-1420
db:BIDid:41925

LAST UPDATE DATE

2022-05-17T02:07:26.287000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2010-1420date:2010-07-25T00:00:00
db:BIDid:41925date:2010-07-23T00:00:00

SOURCES RELEASE DATE

db:IVDid:0e46d7f0-1fb3-11e6-abef-000c29c66e3ddate:2010-07-25T00:00:00
db:CNVDid:CNVD-2010-1420date:2010-07-25T00:00:00
db:BIDid:41925date:2010-07-23T00:00:00