PT-2019-4583 · Sap · Sap Gateway
Rafael Fontes Souza
·
Published
2019-07-09
·
Updated
2020-08-24
·
CVE-2019-0319
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
SAP Gateway versions 7.5 through 7.53
Description
The issue allows an attacker to inject content that is displayed as an error message, potentially misleading users into believing the information comes from a legitimate service. This is due to the lack of measures to neutralize special elements, which could allow a remote attacker to impact data integrity.
Recommendations
For SAP Gateway versions 7.5 through 7.53, consider implementing measures to neutralize special elements and validate user input to prevent content injection. As a temporary workaround, restrict access to error messages that could be manipulated by an attacker.
Exploit
Fix
Special Elements Injection
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sap Gateway