PT-2019-4570 · Sap · Sap Manufacturing Integration/Intelligence
Published
2019-02-15
·
Updated
2019-03-12
·
CVE-2019-0267
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
SAP Manufacturing Integration and Intelligence versions 15.0 through 15.2
Description
The issue is related to the lack of Anti-XSRF tokens in the Illuminator Servlet, which could lead to cross-site request forgery (XSRF) attacks if data is posted to the Servlet from an external application. This might allow a remote attacker to gain access to the vulnerable application.
Recommendations
For versions 15.0 through 15.2, consider implementing Anti-XSRF tokens in the Illuminator Servlet to prevent XSRF attacks. As a temporary workaround, restrict access to the Illuminator Servlet to minimize the risk of exploitation.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Manufacturing Integration/Intelligence