Please fill in the following form in order to download the selected Onapsis’ resource. The system will send you a download link to your email.
By registering, you will obtain the following benefits:
- Receive information regarding new/upcoming Onapsis Security Advisories before public release.
- Receive new issue of Onapsis’ SAP Security In-Depth publication before everyone else.
- Free subscription to the Onapsis Security Newsletter.
Further Reading
Missing authorization check in CRM_THTMLB_LOAD_CSS leads to arbitrary read of reports source code
Missing authorization check in CRM_THTMLB_LOAD_CSS leads to arbitrary read of reports source code Impact on Business A remote, authenticated attacker can read the source code of arbitrary reports from the application server. This has a low impact on the confidentiality of the system and its business applications, potentially exposing sensitive logic or information embedded in…
Reflected XSS in BSP Application CRM_THTMLB_UTIL
Reflected XSS in BSP Application CRM_THTMLB_UTIL Impact on Business A remote attacker can exploit a Reflected Cross-Site Scripting (XSS) vulnerability to execute arbitrary JavaScript code in the victim’s browser. This can lead to the exfiltration of sensitive user information, unauthorized modifications to the system, or redirection to malicious websites, thereby impacting the confidentiality and integrity…
SAP Netweaver JAVA Enterprise Portal – Translation Worklist Authentication Insecure Deserialization
SAP Netweaver JAVA Enterprise Portal – Translation Worklist Authentication Insecure Deserialization Impact on Business A remote, authenticated attacker can exploit an insecure deserialization vulnerability to execute arbitrary operating system commands on the target system. This has a critical impact on the confidentiality, integrity, and availability of the system and its business applications, potentially allowing full…
