CVE-2019-0305
Published: Jun 12, 2019
Modified: Aug 4, 2024
Description
Java Server Pages (JSPs) provided by the SAP NetWeaver Process Integration (SAP_XIESR and SAP_XITOOL: 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50) do not restrict or incorrectly restrict frame objects or UI layers that belong to another application or domain, resulting in Clickjacking vulnerability. Successful exploitation of this vulnerability leads to unwanted modification of user's data.
| Vendor | Product | Versions |
|---|---|---|
SAP SE | SAP NetWeaver Process Integration(SAP_XIESR and SAP_XITOOL) | affected < 7.10 to 7.11affected < 7.2affected < 7.3affected < 7.31affected < 7.4+1 more versions |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now