ID

VAR-201207-0713


TITLE

SAP Netweaver Cross Site Scripting and Information Disclosure Vulnerabilities

Trust: 0.3

sources: BID: 55810

DESCRIPTION

SAP Netweaver is prone to a cross-site scripting vulnerability and an information-disclosure vulnerability. An attacker may leverage these issues to obtain potentially sensitive information and to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks. SAP Netweaver 7.0 is vulnerable; other versions may also be affected.

Trust: 0.3

sources: BID: 55810

AFFECTED PRODUCTS

vendor:sapmodel:netweaverscope:eqversion:7.0

Trust: 0.3

sources: BID: 55810

THREAT TYPE

network

Trust: 0.3

sources: BID: 55810

TYPE

Unknown

Trust: 0.3

sources: BID: 55810

EXTERNAL IDS

db:BIDid:55810

Trust: 0.3

sources: BID: 55810

REFERENCES

url:http://www.sap.com/

Trust: 0.3

url:http://erpscan.com/advisories/dsecrg-12-031-sap-netweaver-mobile-xs/

Trust: 0.3

url:http://erpscan.com/advisories/dsecrg-12-032-sap-netweaver-7-0-information-disclosure/

Trust: 0.3

sources: BID: 55810

CREDITS

Dmitry Chastuchin of ERPScan

Trust: 0.3

sources: BID: 55810

SOURCES

db:BIDid:55810

LAST UPDATE DATE

2022-05-17T02:07:17.560000+00:00


SOURCES UPDATE DATE

db:BIDid:55810date:2012-07-30T00:00:00

SOURCES RELEASE DATE

db:BIDid:55810date:2012-07-30T00:00:00