A "high risk" vulnerability has been identified in Google Chrome versions prior to 126.0.6478.54 for Linux and versions before 126.0.6478.56/57 for Windows and Mac, according to CERT-In, a division of India's Ministry of Electronics & Information Technology. The dangers include vulnerabilities in SAP products that allow cross-site scripting and expose sensitive data, as well as attackers running arbitrary code and creating denial of service.
The affected SAP products include SAP Financial Consolidation, NetWeaver AS Java (Meta Model Repository), NetWeaver AS Java (Guided Procedures), NetWeaver and ABAP platform, Document Builder (HTTP service), Bank Account Management, and others.
“Multiple vulnerabilities have been reported in Google Chrome which could allow a remote attacker to execute arbitrary code on the targeted system,” said the CERT-In advisory.
As per the cyber agency, these vulnerabilities exist in Google Chrome due to Type Confusion in V8; Use after free in Dawn, V8, BrowserUI, Audio; Inappropriate implementation in Dawn, DevTools, Memory Allocator, Downloads; Heap buffer overflow in Tab Groups, Tab Strip and Policy Bypass in CORS.
A remote attacker could exploit these vulnerabilities by persuading a victim to visit a specially crafted web page. The vulnerabilities reported in SAP Products could allow an attacker to perform Cross-site scripting (XSS), Missing authorisation checks, File upload, obtain sensitive information, or cause denial of service conditions on the targeted system, according to the cyber agency.
CERT-In has suggested users apply appropriate security updates as recommended by the companies to stay away from phishing attacks.
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.