New User, Welcome!     Login

SAP Enterprise Portal

[Onapsis Security Advisory 2011-005] SAP Enterprise Portal Path Disclosure

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Onapsis Security Advisory 2011-005: SAP Enterprise Portal Path Disclosure

This advisory can be downloaded in PDF format from http://www.onapsis.com/.
By downloading this advisory from the Onapsis Resource Center, you will gain access to beforehand information on upcoming advisories, presentations
and new research projects from the Onapsis Research Labs, as well as exclusive access to special promotions for upcoming trainings and conferences.



[Onapsis Security Advisory 2010-004] SAP J2EE Authentication Phishing Vector

platform, which enables the development and execution of Java solutions
in SAP
landscapes.

The J2EE Engine is the component on which, for example, the SAP
Enterprise Portal solution is built and executed.


5. Vulnerability Details
========================


[Onapsis Security Advisory 2010-005] SAP J2EE Telnet Administration Security Check Bypass

==================================

The SAP J2EE Engine is a key component of the SAP NetWeaver application platform, which enables the development and execution of Java solutions in SAP
landscapes.

The J2EE Engine is the component on which, for example, the SAP Enterprise Portal solution is built and executed.


5. Vulnerability Details
========================


[Onapsis Security Advisory 2010-006] SAP J2EE Web Services Navigator Cross-Site Scripting

The SAP J2EE Engine is a key component of the SAP NetWeaver
application platform, which enables the development and execution of
Java solutions in SAP landscapes.

The J2EE Engine is the component on which, for example, the SAP
Enterprise Portal solution is built and executed.


5. Vulnerability Details
========================


[Onapsis Security Advisory 2010-003] SAP WebDynpro Runtime XSS/CSS Injection

professional business
applications. It is based on the Model View Controller (MVC) paradigm
which ensures that the business logic is separated from the presentation
logic.

The SAP Enterprise Portal and Web Dynpro for Java are the strategic user
interface technologies of SAP and are based on the SAP Web Application
Server
(WebAS) Java.



[Onapsis Security Advisory 2011-011] Oracle JD Edwards JDENET Buffer Overflow

Fortune-500 companies and governmental entities.

Our star product, Onapsis X1, enables our customers to perform automated Security & Compliance Audits, Vulnerability Assessments and Penetration Tests
over their SAP platform, helping them enforce compliance requirements, decrease financial fraud risks an reduce audit costs drastically.

Some of our featured services include SAP Penetration Testing, SAP Gateway & RFC security, SAP Enterprise Portal security assessment, Security Support
for SAP Implementations and Upgrades, SAP System Hardening and SAP Technical Security Audits.

For further information about our solutions, please contact us at info@onapsis.com and visit our website at www.onapsis.com.

Copyright (c) 2011 Onapsis SRL. All rights reserved.

[Onapsis Security Advisory 2011-008] Oracle JD Edwards JDENET CallObjectKernel Remote Command Execution

Fortune-500 companies and governmental entities.

Our star product, Onapsis X1, enables our customers to perform automated Security & Compliance Audits, Vulnerability Assessments and Penetration Tests
over their SAP platform, helping them enforce compliance requirements, decrease financial fraud risks an reduce audit costs drastically.

Some of our featured services include SAP Penetration Testing, SAP Gateway & RFC security, SAP Enterprise Portal security assessment, Security Support
for SAP Implementations and Upgrades, SAP System Hardening and SAP Technical Security Audits.

For further information about our solutions, please contact us at info@onapsis.com and visit our website at www.onapsis.com.

Copyright (c) 2011 Onapsis SRL. All rights reserved.

[Onapsis Security Advisory 2010-007] SAP Management Console Multiple Denial of Service

critical platforms in world-wide customers, such as Fortune-500 companies and governmental entities.

Our star product, Onapsis X1, enables our customers to perform automated Security & Compliance Audits, Vulnerability Assessments and Penetration Tests
over their SAP platform, helping them enforce compliance requirements, decrease financial fraud risks an reduce audit costs drastically.

Some of our featured services include SAP Penetration Testing, SAP Gateway & RFC security, SAP Enterprise Portal security assessment, Security Support
for SAP Implementations and Upgrades, SAP System Hardening and SAP Technical Security Audits.

For further information about our solutions, please contact us at info@onapsis.com and visit our website at www.onapsis.com.



[Onapsis Security Advisory 2010-002] SAP J2EE Engine MDB Path Traversal

protection of
critical platforms in world-wide customers, such as Fortune-500
companies and governmental entities.

Some of our featured services include SAP Penetration Testing, SAP
Gateway & RFC security, SAP Enterprise Portal security assessment,
Security Support
for SAP Implementations and Upgrades, SAP System Hardening and SAP
Technical Security Audits.

For further information about our solutions, please contact us at

[Onapsis Security Advisory 2011-016] SAP WebAS Malicious SAP Shortcut Generation

critical platforms in world-wide customers, such as Fortune-100 companies and governmental entities.

Our star product, Onapsis X1, enables our customers to perform automated Security & Compliance Audits, Vulnerability Assessments and Penetration Tests
over their SAP platform, helping them enforce compliance requirements, decrease financial fraud risks an reduce audit costs drastically.

Some of our featured services include SAP Penetration Testing, SAP Gateway & RFC security, SAP Enterprise Portal security assessment, Security Support
for SAP Implementations and Upgrades, SAP System Hardening and SAP Technical Security Audits.

For further information about our solutions, please contact us at info@onapsis.com and visit our website at www.onapsis.com.

Copyright (c) 2011 Onapsis SRL. All rights reserved.

[Onapsis Security Advisory 2011-010] Oracle JD Edwards JDENET Remote Logging Deactivation

Fortune-500 companies and governmental entities.

Our star product, Onapsis X1, enables our customers to perform automated Security & Compliance Audits, Vulnerability Assessments and Penetration Tests
over their SAP platform, helping them enforce compliance requirements, decrease financial fraud risks an reduce audit costs drastically.

Some of our featured services include SAP Penetration Testing, SAP Gateway & RFC security, SAP Enterprise Portal security assessment, Security Support
for SAP Implementations and Upgrades, SAP System Hardening and SAP Technical Security Audits.

For further information about our solutions, please contact us at info@onapsis.com and visit our website at www.onapsis.com.

Copyright (c) 2011 Onapsis SRL. All rights reserved.

[Onapsis Security Advisory 2010-001] SAP WebAS Integrated ITS Remote Command Execution

business platforms, protecting their information and decreasing financial fraud risks.

Onapsis is built upon a team of world-renowned experts in the SAP security field, with several years of experience in the assessment and protection of
critical platforms in world-wide customers, such as Fortune-500 companies and governmental entities.

Some of our featured services include SAP Penetration Testing, SAP Gateway & RFC security, SAP Enterprise Portal security assessment, Security Support
for SAP Implementations and Upgrades, SAP System Hardening and SAP Technical Security Audits.

For further information about our solutions, please contact us at info@onapsis.com and visit our website at www.onapsis.com.



[Onapsis Security Advisory 2011-015] SAP WebAS webrfc Cross-Site Scripting

critical platforms in world-wide customers, such as Fortune-100 companies and governmental entities.

Our star product, Onapsis X1, enables our customers to perform automated Security & Compliance Audits, Vulnerability Assessments and Penetration Tests
over their SAP platform, helping them enforce compliance requirements, decrease financial fraud risks an reduce audit costs drastically.

Some of our featured services include SAP Penetration Testing, SAP Gateway & RFC security, SAP Enterprise Portal security assessment, Security Support
for SAP Implementations and Upgrades, SAP System Hardening and SAP Technical Security Audits.

For further information about our solutions, please contact us at info@onapsis.com and visit our website at www.onapsis.com.

Copyright (c) 2011 Onapsis SRL. All rights reserved.

[Onapsis Security Advisory 2011-014] SAP WebAS Remote Denial of Service

critical platforms in world-wide customers, such as Fortune-100 companies and governmental entities.

Our star product, Onapsis X1, enables our customers to perform automated Security & Compliance Audits, Vulnerability Assessments and Penetration Tests
over their SAP platform, helping them enforce compliance requirements, decrease financial fraud risks an reduce audit costs drastically.

Some of our featured services include SAP Penetration Testing, SAP Gateway & RFC security, SAP Enterprise Portal security assessment, Security Support
for SAP Implementations and Upgrades, SAP System Hardening and SAP Technical Security Audits.

For further information about our solutions, please contact us at info@onapsis.com and visit our website at www.onapsis.com.

Copyright (c) 2011 Onapsis SRL. All rights reserved.

[Onapsis Security Advisory 2011-001] SAP Management Console Unauthenticated Service Restart

critical platforms in world-wide customers, such as Fortune-500 companies and governmental entities.

Our star product, Onapsis X1, enables our customers to perform automated Security & Compliance Audits, Vulnerability Assessments and Penetration Tests
over their SAP platform, helping them enforce compliance requirements, decrease financial fraud risks an reduce audit costs drastically.

Some of our featured services include SAP Penetration Testing, SAP Gateway & RFC security, SAP Enterprise Portal security assessment, Security Support
for SAP Implementations and Upgrades, SAP System Hardening and SAP Technical Security Audits.

For further information about our solutions, please contact us at info@onapsis.com and visit our website at www.onapsis.com.



[Onapsis Security Advisory 2011-003] SAP WebAS ITS Mobile Start Service Multiple Vulnerabilities

critical platforms in world-wide customers, such as Fortune-100 companies and governmental entities.

Our star product, Onapsis X1, enables our customers to perform automated Security & Compliance Audits, Vulnerability Assessments and Penetration Tests
over their SAP platform, helping them enforce compliance requirements, decrease financial fraud risks an reduce audit costs drastically.

Some of our featured services include SAP Penetration Testing, SAP Gateway & RFC security, SAP Enterprise Portal security assessment, Security Support
for SAP Implementations and Upgrades, SAP System Hardening and SAP Technical Security Audits.

For further information about our solutions, please contact us at info@onapsis.com and visit our website at www.onapsis.com.

Copyright (c) 2011 Onapsis SRL. All rights reserved.

[Onapsis Security Advisory 2010-008] Oracle Virtual Server Agent Arbitrary File Access

critical platforms in world-wide customers, such as Fortune-500 companies and governmental entities.

Our star product, Onapsis X1, enables our customers to perform automated Security & Compliance Audits, Vulnerability Assessments and Penetration Tests
over their SAP platform, helping them enforce compliance requirements, decrease financial fraud risks an reduce audit costs drastically.

Some of our featured services include SAP Penetration Testing, SAP Gateway & RFC security, SAP Enterprise Portal security assessment, Security Support
for SAP Implementations and Upgrades, SAP System Hardening and SAP Technical Security Audits.

For further information about our solutions, please contact us at info@onapsis.com and visit our website at www.onapsis.com.



[Onapsis Security Advisory 2011-004] SAP WebAS ITS Mobile Test Service Multiple Vulnerabilities

critical platforms in world-wide customers, such as Fortune-100 companies and governmental entities.

Our star product, Onapsis X1, enables our customers to perform automated Security & Compliance Audits, Vulnerability Assessments and Penetration Tests
over their SAP platform, helping them enforce compliance requirements, decrease financial fraud risks an reduce audit costs drastically.

Some of our featured services include SAP Penetration Testing, SAP Gateway & RFC security, SAP Enterprise Portal security assessment, Security Support
for SAP Implementations and Upgrades, SAP System Hardening and SAP Technical Security Audits.

For further information about our solutions, please contact us at info@onapsis.com and visit our website at www.onapsis.com.

Copyright (c) 2011 Onapsis SRL. All rights reserved.

[Onapsis Security Advisory 2010-010] Oracle Virtual Server Agent Local Privilege Escalation

critical platforms in world-wide customers, such as Fortune-500 companies and governmental entities.

Our star product, Onapsis X1, enables our customers to perform automated Security & Compliance Audits, Vulnerability Assessments and Penetration Tests
over their SAP platform, helping them enforce compliance requirements, decrease financial fraud risks an reduce audit costs drastically.

Some of our featured services include SAP Penetration Testing, SAP Gateway & RFC security, SAP Enterprise Portal security assessment, Security Support
for SAP Implementations and Upgrades, SAP System Hardening and SAP Technical Security Audits.

For further information about our solutions, please contact us at info@onapsis.com and visit our website at www.onapsis.com.



[Onapsis Security Advisory 2011-007] Oracle JD Edwards JDENET Kernel Shutdown

Fortune-500 companies and governmental entities.

Our star product, Onapsis X1, enables our customers to perform automated Security & Compliance Audits, Vulnerability Assessments and Penetration Tests
over their SAP platform, helping them enforce compliance requirements, decrease financial fraud risks an reduce audit costs drastically.

Some of our featured services include SAP Penetration Testing, SAP Gateway & RFC security, SAP Enterprise Portal security assessment, Security Support
for SAP Implementations and Upgrades, SAP System Hardening and SAP Technical Security Audits.

For further information about our solutions, please contact us at info@onapsis.com and visit our website at www.onapsis.com.

Copyright (c) 2011 Onapsis SRL. All rights reserved.

[Onapsis Security Advisory 2011-009] Oracle JD Edwards JDENET SawKernel Remote Password Disclosure

Fortune-500 companies and governmental entities.

Our star product, Onapsis X1, enables our customers to perform automated Security & Compliance Audits, Vulnerability Assessments and Penetration Tests
over their SAP platform, helping them enforce compliance requirements, decrease financial fraud risks an reduce audit costs drastically.

Some of our featured services include SAP Penetration Testing, SAP Gateway & RFC security, SAP Enterprise Portal security assessment, Security Support
for SAP Implementations and Upgrades, SAP System Hardening and SAP Technical Security Audits.

For further information about our solutions, please contact us at info@onapsis.com and visit our website at www.onapsis.com.

Copyright (c) 2011 Onapsis SRL. All rights reserved.

[Onapsis Security Advisory 2010-009] Oracle Virtual Server Agent Remote Command Execution

critical platforms in world-wide customers, such as Fortune-500 companies and governmental entities.

Our star product, Onapsis X1, enables our customers to perform automated Security & Compliance Audits, Vulnerability Assessments and Penetration Tests
over their SAP platform, helping them enforce compliance requirements, decrease financial fraud risks an reduce audit costs drastically.

Some of our featured services include SAP Penetration Testing, SAP Gateway & RFC security, SAP Enterprise Portal security assessment, Security Support
for SAP Implementations and Upgrades, SAP System Hardening and SAP Technical Security Audits.

For further information about our solutions, please contact us at info@onapsis.com and visit our website at www.onapsis.com.



[Onapsis Security Advisory 2011-006] Oracle JD Edwards JDENET Kernel Denial of Service

Fortune-500 companies and governmental entities.

Our star product, Onapsis X1, enables our customers to perform automated Security & Compliance Audits, Vulnerability Assessments and Penetration Tests
over their SAP platform, helping them enforce compliance requirements, decrease financial fraud risks an reduce audit costs drastically.

Some of our featured services include SAP Penetration Testing, SAP Gateway & RFC security, SAP Enterprise Portal security assessment, Security Support
for SAP Implementations and Upgrades, SAP System Hardening and SAP Technical Security Audits.

For further information about our solutions, please contact us at info@onapsis.com and visit our website at www.onapsis.com.

Copyright (c) 2011 Onapsis SRL. All rights reserved.

[Onapsis Security Advisory 2011-013] Oracle JD Edwards JDENET USRBROADCAST Denial of Service

Fortune-500 companies and governmental entities.

Our star product, Onapsis X1, enables our customers to perform automated Security & Compliance Audits, Vulnerability Assessments and Penetration Tests
over their SAP platform, helping them enforce compliance requirements, decrease financial fraud risks an reduce audit costs drastically.

Some of our featured services include SAP Penetration Testing, SAP Gateway & RFC security, SAP Enterprise Portal security assessment, Security Support
for SAP Implementations and Upgrades, SAP System Hardening and SAP Technical Security Audits.

For further information about our solutions, please contact us at info@onapsis.com and visit our website at www.onapsis.com.

Copyright (c) 2011 Onapsis SRL. All rights reserved.

[Onapsis Security Advisory 2011-012] Oracle JD Edwards JDENET Firewall Bypass

Fortune-500 companies and governmental entities.

Our star product, Onapsis X1, enables our customers to perform automated Security & Compliance Audits, Vulnerability Assessments and Penetration Tests
over their SAP platform, helping them enforce compliance requirements, decrease financial fraud risks an reduce audit costs drastically.

Some of our featured services include SAP Penetration Testing, SAP Gateway & RFC security, SAP Enterprise Portal security assessment, Security Support
for SAP Implementations and Upgrades, SAP System Hardening and SAP Technical Security Audits.

For further information about our solutions, please contact us at info@onapsis.com and visit our website at www.onapsis.com.

Copyright (c) 2011 Onapsis SRL. All rights reserved.

[Onapsis Security Advisory 2011-002] SAP Management Console Information Disclosure

critical platforms in world-wide customers, such as Fortune-500 companies and governmental entities.

Our star product, Onapsis X1, enables our customers to perform automated Security & Compliance Audits, Vulnerability Assessments and Penetration Tests
over their SAP platform, helping them enforce compliance requirements, decrease financial fraud risks an reduce audit costs drastically.

Some of our featured services include SAP Penetration Testing, SAP Gateway & RFC security, SAP Enterprise Portal security assessment, Security Support
for SAP Implementations and Upgrades, SAP System Hardening and SAP Technical Security Audits.

For further information about our solutions, please contact us at info@onapsis.com and visit our website at www.onapsis.com.



SAP NetWeaver XSS Vulnerability

#
#############################################################

Introduction:
-------------
The vulnerability found targets the SAP NetWeaver portal. It is
possible to execute JavaScript code in the browser of a valid user
when clicking on a specially crafted URL which can be sent to the
user by email.
This vulnerability can be used to steal the user's session cookie or
redirect him to a phishing website which shows the (faked) login



Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!