SAP security note 2314976, "Content Spoofing in AS Java Web Container", is a program error note released on 03.10.2017. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
AS Java Web Container does not sufficiently encode user-controlled inputs, resulting in a content spoofing vulnerability when error pages are displayed.
Solution
Update AS Java to the latest version. See the SP Patch Level section of this SAP Note for details.
Reason and prerequisites
Content spoofing is an attack technique used to trick a user into believing that certain content appearing on a website is legitimate and not from an external source. This attack is typically used as, or in conjunction with, social engineering because it exploits a code-based vulnerability and a user’s trust.
CVSS
Score 0
Affected components
- ENGINEAPI 7.10 to 7.11
- ENGINEAPI 7.30
- ENGINEAPI 7.31
- ENGINEAPI 7.40
Full note on SAP: SAP Support Launchpad note 2314976
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
