CERT-In Vulnerability Note
CIVN-2012-0104
Microsoft SQL Server Report Manager Reflected Cross Site Scripting Vulnerability
Original Issue Date:October 10, 2012
Severity Rating: MEDIUM
Systems Affected
- Microsoft SQL Server 2000 SP2
- Microsoft SQL Server 2005 Express Edition with Advanced Serv SP4
- Microsoft SQL Server 2005 Itanium Edition SP4
- Microsoft SQL Server 2005 x64 Edition SP4
- Microsoft SQL Server 2008 32-bit SP2
- Microsoft SQL Server 2008 32-bit SP3
- Microsoft SQL Server 2008 itanium SP2
- Microsoft SQL Server 2008 itanium SP3
- Microsoft SQL Server 2008 x64 SP2
- Microsoft SQL Server 2008 x64 SP3
Overview
A vulnerability has been reported in Microsoft SQL Server Report Manager which could allow a remote attacker to launch a reflected cross-site scripting attacks.
Description
The vulnerability is caused due to insufficient validation and sanitization of user-supplied request parameters processed by the affected software before returning the input to the users browser session. An unauthenticated, remote attacker could exploit this vulnerability by enticing users to lick a malicious URL which contains malicious crafted parameters. Upon execution, the URL may return malicious content to the users browser session. Successful exploitation of this vulnerability could allow remote attacker to execute arbitrary script code in the users browser session & allows access to sensitive information or perform actions with the privileges of currently logged-in user.
Note: SQL Server systems that do not have SQL Server Reporting Service installed are not affected by this vulnerability.
Workaround
- Enable Internet Explorer 8, Internet Explorer 9, and Internet Explorer 10 XSS filter for Intranet Zone
Solution
Apply appropriate patches as mentioned in Microsoft Security Bulletin
MS12-070
Vendor Information
Microsoft
http://technet.microsoft.com/en-us/security/bulletin/ms12-070
References
CISCO
http://tools.cisco.com/security/center/viewAlert.x?alertId=27094
Securityfocus
http://www.securityfocus.com/bid/55783
SecurityTracker
http://www.securitytracker.com/id/1027623
CVE Name
CVE-2012-2552
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|