First published: Wed Jun 12 2019(Updated: )
Java Server Pages (JSPs) provided by the SAP NetWeaver Process Integration (SAP_XIESR and SAP_XITOOL: 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50) do not restrict or incorrectly restrict frame objects or UI layers that belong to another application or domain, resulting in Clickjacking vulnerability. Successful exploitation of this vulnerability leads to unwanted modification of user's data.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP NetWeaver Process Integration | =7.10 | |
SAP NetWeaver Process Integration | =7.11 | |
SAP NetWeaver Process Integration | =7.20 | |
SAP NetWeaver Process Integration | =7.30 | |
SAP NetWeaver Process Integration | =7.31 | |
SAP NetWeaver Process Integration | =7.40 | |
SAP NetWeaver Process Integration | =7.50 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-0305 is medium with a score of 4.3.
The affected software versions of CVE-2019-0305 are SAP NetWeaver Process Integration 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, and 7.50.
The Clickjacking vulnerability in CVE-2019-0305 occurs due to Java Server Pages (JSPs) provided by the SAP NetWeaver Process Integration not properly restricting frame objects or UI layers from another application or domain, allowing potential clickjacking attacks.
To fix the CVE-2019-0305 vulnerability, it is recommended to apply the necessary patches provided by SAP and update the SAP NetWeaver Process Integration software to the latest version.
You can find more information about CVE-2019-0305 on the SAP support portal at [https://launchpad.support.sap.com/#/notes/2755502](https://launchpad.support.sap.com/#/notes/2755502) and the SAP Community Network wiki at [https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=521864242](https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=521864242).