SAP Manufacturing Integration and Intelligence, versions 15.0, 15.1 and 15.2, (Illuminator Servlet) currently does not provide Anti-XSRF tokens. This might lead to XSRF attacks in case the data is being posted to the Servlet from an external application.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/106990 | vdb entry third party advisory |
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=510922943 | vendor advisory |
https://launchpad.support.sap.com/#/notes/2686535 | permissions required vendor advisory |