Release date: 2011-11-11
Updated on: 2011-11-23
Affected Systems:
SAP NetWeaver
Description:
--------------------------------------------------------------------------------
SAP NetWeaver is the integrated technology platform of SAP and the technical foundation of all SAP applications since SAP Business Suite.
The bw doc metadata in SAP NetWeaver has Multiple XSS attack vulnerabilities. Attackers can trick users to click malicious links to execute malicious scripts and leak information.
<* Source: Alexander R Polyakov
Dmitriy Chastuchin
Link: http://erpscan.com/advisories/dsecrg-11-037-sap-bw-doc-multiple-xss/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
SAP
---
SAP has released a Security Bulletin (DSECRG-11-037) and patches for this:
DSECRG-11-037: sap bw Doc-Multiple XSS
Link: http://erpscan.com/advisories/dsecrg-11-037-sap-bw-doc-multiple-xss/