CVE-2018-2502

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
11/12/2018
Last modified:
07/01/2019

Description

TRACE method is enabled in SAP Business One Service Layer . Attacker can use XST (Cross Site Tracing) attack if frontend applications that are using Service Layer has a XSS vulnerability. This has been fixed in SAP Business One Service Layer (B1_ON_HANA, versions 9.2, 9.3).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sap:business_one_on_hana:9.2:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_one_on_hana:9.3:*:*:*:*:*:*:*