Skip links
Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2019-0267 Cross site request forgery in implementation of Manufacturing Integration and Intelligence, SAP security note 2686535

Description

MII Illuminator Servlet currently does not provide Anti-XSRF tokens. This might lead to XSRF attacks in case the data is being posted to the Servlet from an external application.

Available fix and Supported packages

  • XMII | 15.0 | 15.0
  • XMII | 15.1 | 15.1
  • XMII | 15.2 | 15.2
  • MII_ADMIN 15.0 | SP009 | 000005
  • MII_ADMIN 15.1 | SP006 | 000008
  • MII_ADMIN 15.2 | SP000 | 000004
  • XMII 15.0 | SP009 | 000010
  • XMII 15.1 | SP006 | 000023
  • XMII 15.2 | SP000 | 000012

Affected component

    MFG-MII
    SAP Manufacturing Integration and Intelligence

CVSS

Score: 6.3
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L

PoC

Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.

URL

https://launchpad.support.sap.com/#/notes/2686535

TAGS

#MII
#Illuminator
#XSRF
#&160-CVE-2019-0267

More to explorer

Special offer for SAP Security Udemy course!

$ 9.99

Join “SAP Security Core Concepts and Security Administration” which is part of the Blackhat course series.