CVE-2019-0305 Information
Feb 14, 2021
cve
Description
Java Server Pages (JSPs) provided by the SAP NetWeaver Process Integration (SAP_XIESR and SAP_XITOOL: 7.10 to 7.11 7.20 7.30 7.31 7.40 7.50) do not restrict or incorrectly restrict frame objects or UI layers that belong to another application or domain resulting in Clickjacking vulnerability. Successful exploitation of this vulnerability leads to unwanted modification of user’s data.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Reference
https://launchpad.support.sap.com//notes/2755502 https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=521864242
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
LOW
Base Score
NONE
Base Severity
4.3
Share on: