First published: Tue Dec 11 2018(Updated: )
TRACE method is enabled in SAP Business One Service Layer . Attacker can use XST (Cross Site Tracing) attack if frontend applications that are using Service Layer has a XSS vulnerability. This has been fixed in SAP Business One Service Layer (B1_ON_HANA, versions 9.2, 9.3).
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sap Business One On Hana | =9.2 | |
Sap Business One On Hana | =9.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.