Release date: 2011-11-11
Updated on: 2011-11-23
Affected Systems:
SAP NetWeaver
Description:
--------------------------------------------------------------------------------
SAP NetWeaver is the integrated technology platform of SAP and the technical foundation of all SAP applications since SAP Business Suite.
Sap gui bapi Explorer has an XSS vulnerability in implementation. Malicious users can exploit this vulnerability to insert malicious scripts on the server to illegally execute arbitrary functions or access the OS.
<* Source: Dmitriy Chastuhin
Link: http://erpscan.com/advisories/dsecrg-11-035-sap-gui-bapi-explorer-unauthorized-execution-of-function
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
SAP
---
SAP has released a Security Bulletin (DSECRG-11-035) and patches for this:
DSECRG-11-035: sap gui bapi Explorer-Unauthorized Execution Of Function
Link: http://erpscan.com/advisories/dsecrg-11-035-sap-gui-bapi-explorer-unauthorized-execution-of-function