PT-2019-11225 · Sap · Sap Netweaver Process Integration

Publicado

2019-06-12

·

Atualizado

2021-07-21

·

CVE-2019-0305

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: SAP NetWeaver Process Integration versions 7.10 through 7.11 SAP NetWeaver Process Integration version 7.20 SAP NetWeaver Process Integration version 7.30 SAP NetWeaver Process Integration version 7.31 SAP NetWeaver Process Integration version 7.40 SAP NetWeaver Process Integration version 7.50
Description: The issue arises from the failure of Java Server Pages (JSPs) to properly restrict frame objects or UI layers from other applications or domains, leading to a Clickjacking issue. This can result in the unwanted modification of a user's data if the vulnerability is successfully exploited.
Recommendations: For SAP NetWeaver Process Integration versions 7.10 through 7.11, update the JSPs to properly restrict frame objects or UI layers. For SAP NetWeaver Process Integration version 7.20, update the JSPs to properly restrict frame objects or UI layers. For SAP NetWeaver Process Integration version 7.30, update the JSPs to properly restrict frame objects or UI layers. For SAP NetWeaver Process Integration version 7.31, update the JSPs to properly restrict frame objects or UI layers. For SAP NetWeaver Process Integration version 7.40, update the JSPs to properly restrict frame objects or UI layers. For SAP NetWeaver Process Integration version 7.50, update the JSPs to properly restrict frame objects or UI layers.

Correção

Clickjacking

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-0305

Produtos afetados

Sap Netweaver Process Integration