PT-2019-4583 · Sap · Sap Gateway

Rafael Fontes Souza

·

Publicado

2019-07-09

·

Atualizado

2020-08-24

·

CVE-2019-0319

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions SAP Gateway versions 7.5 through 7.53
Description The issue allows an attacker to inject content that is displayed as an error message, potentially misleading users into believing the information comes from a legitimate service. This is due to the lack of measures to neutralize special elements, which could allow a remote attacker to impact data integrity.
Recommendations For SAP Gateway versions 7.5 through 7.53, consider implementing measures to neutralize special elements and validate user input to prevent content injection. As a temporary workaround, restrict access to error messages that could be manipulated by an attacker.

Exploit

Correção

Special Elements Injection

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2020-00643
CVE-2019-0319

Produtos afetados

Sap Gateway