PT-2019-11225 · Sap · Sap Netweaver Process Integration

Published

2019-06-12

·

Updated

2021-07-21

·

CVE-2019-0305

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: SAP NetWeaver Process Integration versions 7.10 through 7.11 SAP NetWeaver Process Integration version 7.20 SAP NetWeaver Process Integration version 7.30 SAP NetWeaver Process Integration version 7.31 SAP NetWeaver Process Integration version 7.40 SAP NetWeaver Process Integration version 7.50
Description: The issue arises from the failure of Java Server Pages (JSPs) to properly restrict frame objects or UI layers from other applications or domains, leading to a Clickjacking issue. This can result in the unwanted modification of a user's data if the vulnerability is successfully exploited.
Recommendations: For SAP NetWeaver Process Integration versions 7.10 through 7.11, update the JSPs to properly restrict frame objects or UI layers. For SAP NetWeaver Process Integration version 7.20, update the JSPs to properly restrict frame objects or UI layers. For SAP NetWeaver Process Integration version 7.30, update the JSPs to properly restrict frame objects or UI layers. For SAP NetWeaver Process Integration version 7.31, update the JSPs to properly restrict frame objects or UI layers. For SAP NetWeaver Process Integration version 7.40, update the JSPs to properly restrict frame objects or UI layers. For SAP NetWeaver Process Integration version 7.50, update the JSPs to properly restrict frame objects or UI layers.

Fix

Clickjacking

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-0305

Affected Products

Sap Netweaver Process Integration