PT-2018-15498 · Sap · S4Fnd+1

Publicado

2018-02-14

·

Atualizado

2018-03-07

·

CVE-2018-2364

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SAP CRM WebClient UI versions 7.01, 7.31, 7.46, 7.47, 7.48, 8.00, 8.01 S4FND version 1.02
Description The issue is related to insufficient validation and/or encoding of hidden fields, resulting in a Cross-Site Scripting (XSS) issue.
Recommendations For SAP CRM WebClient UI versions 7.01, 7.31, 7.46, 7.47, 7.48, 8.00, 8.01, update to a version that properly validates and encodes hidden fields. For S4FND version 1.02, update to a version that properly validates and encodes hidden fields. As a temporary workaround, consider restricting access to sensitive areas of the application to minimize the risk of exploitation.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-2364

Produtos afetados

S4Fnd
Sap Crm Webclient Ui