cbcvebase.
CVE-2019-0305
published 2019-06-12

CVE-2019-0305: Java Server Pages (JSPs) provided by the SAP NetWeaver Process Integration (SAP_XIESR and SAP_XITOOL: 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50) do not…

medium4.3CVSS 3.0
AVNACLPRNUIRSUCNILAN
Java Server Pages (JSPs) provided by the SAP NetWeaver Process Integration (SAP_XIESR and SAP_XITOOL: 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50) do not restrict or incorrectly restrict frame objects or UI layers that belong to another application or domain, resulting in Clickjacking vulnerability. Successful exploitation of this vulnerability leads to unwanted modification of user's data.

Affected

13 ranges
VendorProductVersion rangeFixed in
sapnetweaver_process_integration
sapnetweaver_process_integration
sapnetweaver_process_integration
sapnetweaver_process_integration
sapnetweaver_process_integration
sapnetweaver_process_integration
sapnetweaver_process_integration
sap_sesap_netweaver_process_integration< 7.10 to 7.117.10 to 7.11
sap_sesap_netweaver_process_integration< 7.27.2
sap_sesap_netweaver_process_integration< 7.37.3
sap_sesap_netweaver_process_integration< 7.317.31
sap_sesap_netweaver_process_integration< 7.47.4
sap_sesap_netweaver_process_integration< 7.57.5