Release date: 2011-11-11
Updated on: 2011-11-23
Affected Systems:
SAP NetWeaver
Description:
--------------------------------------------------------------------------------
SAP NetWeaver is the integrated technology platform of SAP and the technical foundation of all SAP applications since SAP Business Suite.
SAP NetWaver Virus Scan Interface has multiple cross-site scripting vulnerabilities, causing malicious script execution and information leakage.
<* Source: Dmitriy Evdokimov
Link: http://erpscan.com/advisories/dsecrg-11-036-sap-netwaver-virus-scan-interface-multiple-xss/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
SAP
---
SAP has released a Security Bulletin (DSECRG-11-036) and patches for this:
DSECRG-11-036: SAP NetWaver Virus Scan Interface-Multiple XSS
Link: http://erpscan.com/advisories/dsecrg-11-036-sap-netwaver-virus-scan-interface-multiple-xss/