ID

VAR-201011-0284


TITLE

SAP NetWeaver SQL Monitor Multiple Cross-Site Scripting Vulnerabilities

Trust: 0.8

sources: IVD: 5de2084e-1fa8-11e6-abef-000c29c66e3d // CNVD: CNVD-2010-2847

DESCRIPTION

SAP NetWeaver is the technical foundation for SAP Business Suite solutions, SAP xApps composite applications, partner solutions, and custom applications. The ConnectionMonitorServlet and CatalogBufferMonitorServlet scripts included in SAP NetWeaver lack sufficient filtering for the connid and reqTableColumns parameters. Attackers can send links to administrators to obtain sensitive information such as COOKIE. The SQL Monitor of SAP NetWeaver is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied input. An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks

Trust: 0.99

sources: CNVD: CNVD-2010-2847 // BID: 44904 // IVD: 5de2084e-1fa8-11e6-abef-000c29c66e3d

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.8

sources: IVD: 5de2084e-1fa8-11e6-abef-000c29c66e3d // CNVD: CNVD-2010-2847

AFFECTED PRODUCTS

vendor:sapmodel:netweaverscope:eqversion:7.0

Trust: 1.1

vendor:sapmodel:netweaverscope:eqversion:7.02

Trust: 0.9

vendor:sapmodel:netweaverscope:eqversion:7.01

Trust: 0.9

vendor:sapmodel:netweaverscope:eqversion:7.02*

Trust: 0.2

vendor:sapmodel:netweaverscope:eqversion:7.01*

Trust: 0.2

sources: IVD: 5de2084e-1fa8-11e6-abef-000c29c66e3d // CNVD: CNVD-2010-2847 // BID: 44904

CVSS

SEVERITY

CVSSV2

CVSSV3

IVD: 5de2084e-1fa8-11e6-abef-000c29c66e3d
value: LOW

Trust: 0.2

IVD: 5de2084e-1fa8-11e6-abef-000c29c66e3d
severity: NONE
baseScore: NONE
vectorString: NONE
accessVector: NONE
accessComplexity: NONE
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: UNKNOWN

Trust: 0.2

sources: IVD: 5de2084e-1fa8-11e6-abef-000c29c66e3d

THREAT TYPE

network

Trust: 0.3

sources: BID: 44904

TYPE

Input Validation Error

Trust: 0.3

sources: BID: 44904

PATCH

title:SAP NetWeaver SQL Monitor patch for multiple cross-site scripting vulnerabilitiesurl:https://www.cnvd.org.cn/patchinfo/show/1765

Trust: 0.6

sources: CNVD: CNVD-2010-2847

EXTERNAL IDS

db:BIDid:44904

Trust: 0.9

db:CNVDid:CNVD-2010-2847

Trust: 0.8

db:IVDid:5DE2084E-1FA8-11E6-ABEF-000C29C66E3D

Trust: 0.2

sources: IVD: 5de2084e-1fa8-11e6-abef-000c29c66e3d // CNVD: CNVD-2010-2847 // BID: 44904

REFERENCES

url:http://dsecrg.com/pages/vul/show.php?id=156http

Trust: 0.6

url:http://dsecrg.com/pages/vul/show.php?id=156

Trust: 0.3

url:http://www.sap.com/

Trust: 0.3

url:https://service.sap.com/sap/support/notes/1391770

Trust: 0.3

sources: CNVD: CNVD-2010-2847 // BID: 44904

CREDITS

a.polyakov and a.troshichev from Digital Security Research Group

Trust: 0.3

sources: BID: 44904

SOURCES

db:IVDid:5de2084e-1fa8-11e6-abef-000c29c66e3d
db:CNVDid:CNVD-2010-2847
db:BIDid:44904

LAST UPDATE DATE

2022-05-17T02:04:50.268000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2010-2847date:2010-11-18T00:00:00
db:BIDid:44904date:2010-11-17T00:00:00

SOURCES RELEASE DATE

db:IVDid:5de2084e-1fa8-11e6-abef-000c29c66e3ddate:2010-11-18T00:00:00
db:CNVDid:CNVD-2010-2847date:2010-11-18T00:00:00
db:BIDid:44904date:2010-11-17T00:00:00