Description
TRACE method is enabled in SAP Business One Service Layer . Attacker can use XST (Cross Site Tracing) attack if frontend applications that are using Service Layer has a XSS vulnerability. This has been fixed in SAP Business One Service Layer (B1_ON_HANA, versions 9.2, 9.3).
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-14357 | TRACE method is enabled in SAP Business One Service Layer . Attacker can use XST (Cross Site Tracing) attack if frontend applications that are using Service Layer has a XSS vulnerability. This has been fixed in SAP Business One Service Layer (B1_ON_HANA, versions 9.2, 9.3). |
References
History
No history.
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2024-08-05T04:21:34.181Z
Reserved: 2017-12-15T00:00:00.000Z
Link: CVE-2018-2502
No data.
Status : Modified
Published: 2018-12-11T22:29:00.530
Modified: 2024-11-21T04:03:55.543
Link: CVE-2018-2502
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD