Skip links
Arpine Maghakyan

Arpine Maghakyan

Security Researcher of RedRays.

XSRF protection for applications based on WebClient UI, SAP security note 1532369

Description

This security note has been updated. For details, see security note 1570290.

This note introduces general XSRF protection for applications that are based on the WebClient UI.

Available fix and Supported packages

  • CRMUIF | 520 | 520
  • CRMUIF | 600 | 600
  • WEBCUIF | 700 | 700
  • WEBCUIF | 730 | 730
  • CRMUIF 600 | SAPK-60011INCRMUIF |
  • CRMUIF 520 | SAPK-52013INCRMUIF |
  • WEBCUIF 700 | SAPK-70009INWEBCUIF |
  • WEBCUIF 730 | SAPK-73001INWEBCUIF |

Affected component

    CA-WUI-UI-RT
    Runtime Environment

CVSS

Score: 0

Exploit

Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.

URL

https://launchpad.support.sap.com/#/notes/1532369

TAGS

#-

More to explorer

SAP Cloud Connector Certificate Validation Issue

Date of Release: February 13, 2024 Advisory ID: CVE-2024-25642 Affected Software: SAP Cloud Connector Versions Affected: 2.15.0 to 2.16.1 Vulnerability Summary:A critical vulnerability,