First published: Fri Feb 15 2019(Updated: )
SAP Manufacturing Integration and Intelligence, versions 15.0, 15.1 and 15.2, (Illuminator Servlet) currently does not provide Anti-XSRF tokens. This might lead to XSRF attacks in case the data is being posted to the Servlet from an external application.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Manufacturing Integration and Intelligence | =15.0 | |
SAP Manufacturing Integration and Intelligence | =15.1 | |
SAP Manufacturing Integration and Intelligence | =15.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-0267 is classified as medium, indicating a moderate risk for XSRF attacks.
To fix CVE-2019-0267, implement Anti-XSRF tokens in the application to protect against cross-site request forgery.
CVE-2019-0267 affects SAP Manufacturing Integration and Intelligence versions 15.0, 15.1, and 15.2.
CVE-2019-0267 allows XSRF (Cross-Site Request Forgery) attacks due to the lack of Anti-XSRF tokens.
Yes, SAP has provided guidance on mitigating CVE-2019-0267, including patches that can be applied to affected versions.