SAP Manufacturing Integration and Intelligence, versions 15.0, 15.1 and 15.2, (Illuminator Servlet) currently does not provide Anti-XSRF tokens. This might lead to XSRF attacks in case the data is being posted to the Servlet from an external application.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-1040 | SAP Manufacturing Integration and Intelligence, versions 15.0, 15.1 and 15.2, (Illuminator Servlet) currently does not provide Anti-XSRF tokens. This might lead to XSRF attacks in case the data is being posted to the Servlet from an external application. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2024-08-04T17:44:16.407Z
Reserved: 2018-11-26T00:00:00.000Z
Link: CVE-2019-0267
No data.
Status : Modified
Published: 2019-02-15T18:29:02.320
Modified: 2024-11-21T04:16:36.360
Link: CVE-2019-0267
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD