Skip links

Error in Open SQL monitors servlet application, SAP security note 1391770

Description

There was a security breach in the Open SQL monitors servlet application due to possible cross-site scripting (XSS) attacks.

Available fix and Supported packages

  • SAP-JEE | 6.40 | 6.40
  • SAP_JTECHS | 7.00 | 7.02
  • J2EE-APPS | 7.10 | 7.11
  • J2EE-APPS | 7.20 | 7.20
  • J2EE ENGINE APPLICATIONS 7.10 | SP006 | 000003
  • J2EE ENGINE APPLICATIONS 7.10 | SP007 | 000002
  • J2EE ENGINE APPLICATIONS 7.10 | SP008 | 000001
  • J2EE ENGINE APPLICATIONS 7.10 | SP009 | 000001
  • J2EE ENGINE APPLICATIONS 7.10 | SP010 | 000000
  • J2EE ENGINE APPLICATIONS 7.11 | SP002 | 000004
  • J2EE ENGINE APPLICATIONS 7.11 | SP003 | 000006
  • J2EE ENGINE APPLICATIONS 7.11 | SP004 | 000000
  • J2EE ENGINE APPLICATIONS 7.20 | SP001 | 000004
  • J2EE ENGINE APPLICATIONS 7.20 | SP002 | 000000
  • SAP J2EE ENGINE 6.40 | SP023 | 000001
  • SAP J2EE ENGINE 6.40 | SP024 | 000001
  • SAP J2EE ENGINE 6.40 | SP025 | 000001
  • SAP JAVA TECH SERVICES 6.40 | SP026 | 000000
  • SAP JAVA TECH SERVICES 7.00 | SP017 | 000015
  • SAP JAVA TECH SERVICES 7.00 | SP018 | 000017
  • SAP JAVA TECH SERVICES 7.00 | SP019 | 000015
  • SAP JAVA TECH SERVICES 7.00 | SP020 | 000013
  • SAP JAVA TECH SERVICES 7.00 | SP021 | 000006
  • SAP JAVA TECH SERVICES 7.00 | SP022 | 000000

Affected component

    BC-JAS-PER-SQL
    Relational Persistence: Open SQLJ, Open JDBC

CVSS

Score: 0

Exploit

Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.

URL

https://launchpad.support.sap.com/#/notes/1391770

TAGS

#Reflexive-cross-site-scripting
#XSS

How to detect over 4100 vulnerabilities in SAP Systems?

More to explorer

Initiating SAP Penetration Testing

►   Pentest, short for penetration testing, refers to a set of processes that simulate an attacker’s actions to identify security vulnerabilities. Companies

SAP Security Patch Day RedRays

May 2024 SAP Security Patch Day

Vulnerability: Multiple vulnerabilities in SAP CX Commerce SAP Component: CEC-SCC-PLA-PL CVE ID: CVE-2019-17495 CVSS Score: 9.8 CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Category: Program error