CVE-2019-0305

Java Server Pages (JSPs) provided by the SAP NetWeaver Process Integration (SAP_XIESR and SAP_XITOOL: 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50) do not restrict or incorrectly restrict frame objects or UI layers that belong to another application or domain, resulting in Clickjacking vulnerability. Successful exploitation of this vulnerability leads to unwanted modification of user's data.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sap:netweaver_process_integration:7.10:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_process_integration:7.11:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_process_integration:7.20:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_process_integration:7.30:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_process_integration:7.31:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_process_integration:7.40:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_process_integration:7.50:*:*:*:*:*:*:*

History

21 Nov 2024, 04:16

Type Values Removed Values Added
References () https://launchpad.support.sap.com/#/notes/2755502 - Permissions Required, Vendor Advisory () https://launchpad.support.sap.com/#/notes/2755502 - Permissions Required, Vendor Advisory
References () https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=521864242 - Vendor Advisory () https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=521864242 - Vendor Advisory

Information

Published : 2019-06-12 15:29

Updated : 2024-11-21 04:16


NVD link : CVE-2019-0305

Mitre link : CVE-2019-0305

CVE.ORG link : CVE-2019-0305


JSON object : View

Products Affected

sap

  • netweaver_process_integration
CWE
CWE-1021

Improper Restriction of Rendered UI Layers or Frames