SAP Security Note
Medium priority
SAP security note 2789866, "[CVE-2019-0337] Cross-Site Scripting (XSS) Vulnerability in Java Proxy Runtime of SAP NetWeaver Process Integration", is a program error note. Below are the symptom and SAP recommended solution.
Description
Symptom
- Non-permanent defacement or modification of displayed content on a website.
- Theft of user authentication information, such as session data.
- Impersonation of the user to access information with the same rights.
Solution
- Code Changes: URL parameters are now properly encoded. Changes have been made to Outbound Java Proxy processing to address the issue.
- Action Required: Apply the relevant support packages and patches referenced in this SAP Security Note.
CVSS
Score 6.1 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
References
- CVE-2019-0337
- Related SAP Notes
Full note on SAP: SAP Support Launchpad note 2789866
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
