Erfassung von Netzanwendungsschwachstellen

EP3709592 Art B1 6. Juli 2022

Anmelder: SAP SE 🇩🇪

Details

Veröffentlichungs-Nr.
EP3709592
Aktenzeichen
EP19200801
Anmeldetag
1. Oktober 2019
Veröffentlichung
6. Juli 2022
Erteilung
6. Juli 2022
Rechtsraum
EP
IPC
G06F11/36
Offizieller Volltext

Abstract

Various examples are directed to systems and methods for detecting vulnerabilities in a web application. A testing utility may direct a plurality of request messages to a web application. The testing utility may be executed at a first computing device and the web application may be executed at a second computing device. The testing utility may determine that a first request message of the plurality of test messages describes a state changing request. The determining may be based at least in part on the first request message and a first response message generated by the web application in response to the first request message. The testing utility may generate a first tampered request message based at least in part on the first request message and direct the first tampered request message to the web application. The testing utility may determine that the first request message indicates a vulnerability of the web application, the determining based at least in part on the first tampered request message and a first traffic-tampered response message generated by the web application in response to the first tampered request message.

Anmelder

Firma
SAP SE
Land
🇩🇪 Deutschland
🇩🇪 SAP

Deutsches Unternehmen, das Unternehmenssoftware für Ressourcenplanung, Datenmanagement und Cloud-Anwendungen entwickelt und vertreibt.

1.422 Patente in unserer Datenbank

Noch Fragen?

Wir helfen Ihnen gerne weiter. Schreiben Sie uns einfach.

Kontakt aufnehmen