PT-2019-11225 · Sap · Sap Netweaver Process Integration
Published
2019-06-12
·
Updated
2021-07-21
·
CVE-2019-0305
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
SAP NetWeaver Process Integration versions 7.10 through 7.11
SAP NetWeaver Process Integration version 7.20
SAP NetWeaver Process Integration version 7.30
SAP NetWeaver Process Integration version 7.31
SAP NetWeaver Process Integration version 7.40
SAP NetWeaver Process Integration version 7.50
Description:
The issue arises from the failure of Java Server Pages (JSPs) to properly restrict frame objects or UI layers from other applications or domains, leading to a Clickjacking issue. This can result in the unwanted modification of a user's data if the vulnerability is successfully exploited.
Recommendations:
For SAP NetWeaver Process Integration versions 7.10 through 7.11, update the JSPs to properly restrict frame objects or UI layers.
For SAP NetWeaver Process Integration version 7.20, update the JSPs to properly restrict frame objects or UI layers.
For SAP NetWeaver Process Integration version 7.30, update the JSPs to properly restrict frame objects or UI layers.
For SAP NetWeaver Process Integration version 7.31, update the JSPs to properly restrict frame objects or UI layers.
For SAP NetWeaver Process Integration version 7.40, update the JSPs to properly restrict frame objects or UI layers.
For SAP NetWeaver Process Integration version 7.50, update the JSPs to properly restrict frame objects or UI layers.
Fix
Clickjacking
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Netweaver Process Integration