SAP security note 2550202, "[CVE-2018-2415] Content Spoofing Vulnerability in NetWeaver Java AS Web Container and HTTP Service", is a note. Below are the symptom and SAP recommended solution.
Description
Symptom
SAP NetWeaver Application Server Java Web Container and HTTP Service do not sufficiently encode user-controlled inputs, resulting in a content spoofing vulnerability when error pages are displayed.
Solution
Update AS Java to the latest version. See the Support Package Patch Level section of this SAP Note for details.
CVSS
Score 4.7 Vector: AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
References
- CVE-2018-2415
Full note on SAP: SAP Support Launchpad note 2550202
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
