PT-2019-4570 · Sap · Sap Manufacturing Integration/Intelligence

Published

2019-02-15

·

Updated

2019-03-12

·

CVE-2019-0267

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SAP Manufacturing Integration and Intelligence versions 15.0 through 15.2
Description The issue is related to the lack of Anti-XSRF tokens in the Illuminator Servlet, which could lead to cross-site request forgery (XSRF) attacks if data is posted to the Servlet from an external application. This might allow a remote attacker to gain access to the vulnerable application.
Recommendations For versions 15.0 through 15.2, consider implementing Anti-XSRF tokens in the Illuminator Servlet to prevent XSRF attacks. As a temporary workaround, restrict access to the Illuminator Servlet to minimize the risk of exploitation.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-00630
CVE-2019-0267

Affected Products

Sap Manufacturing Integration/Intelligence