Rewterz penetration testing services help organizations determine if a cyber attacker can gain access to their critical assets while giving them detailed insights of the overall business impact of a cyber attack.
Before Rewterz got its start, the market was in dire need of a specialized and dedicated information security company. It was nearly impossible for businesses to find a trustworthy provider that could truly cover all of their bases. We wanted to meet this need, giving companies across the globe a chance to get ahead while knowing that their data is in good hands.
Rewterz penetration testing services help organizations determine if a cyber attacker can gain access to their critical assets while giving them detailed insights of the overall business impact of a cyber attack.
Before Rewterz got its start, the market was in dire need of a specialized and dedicated information security company. It was nearly impossible for businesses to find a trustworthy provider that could truly cover all of their bases. We wanted to meet this need, giving companies across the globe a chance to get ahead while knowing that their data is in good hands.
Medium
SAP NetWeaver Enterprise Portal is vulnerable to server-side request forgery, caused by an unspecified flaw. By sending a specially crafted request, an attacker could exploit this vulnerability to conduct SSRF attack.
SAP Business One (Service Layer) could allow a remote authenticated attacker to bypass security restrictions, caused by a missing authorization check flaw. By sending a specially crafted request, an attacker could exploit this vulnerability to bypass access restrictions to perform unauthorized actions.
SAP Business One could allow a local authenticated attacker to bypass security restrictions, caused by a missing authentication check flaw. By sending a specially crafted request, an attacker could exploit this vulnerability to bypass access restrictions
SAP BusinessObjects Business Intelligence Platform (SAP UI5) could allow a remote attacker to conduct phishing attacks, caused by a Reverse Tabnabbing flaw. An attacker could exploit this vulnerability to redirect a victim to arbitrary Web sites.
SAP BusinessObjects Business Intelligence Platform (Crystal Report) is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote authenticated attacker could exploit this vulnerability to inject malicious script into a Web page which would be executed in a victim’s Web browser within the security context of the hosting Web site, once the page is viewed. An attacker could use this vulnerability to steal the victim’s cookie-based authentication credentials.
SAP NetWeaver Development Infrastructure (Notification Service) is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim’s Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim’s cookie-based authentication credentials.
SAP
Current SAP customers should refer to SAP notes for patch information, available from the SAP Web site.
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=582222806