SAP Manufacturing Execution versions - 15.1, 1.5.2, 15.3, 15.4, does not contain some HTTP security headers in their HTTP response. The lack of these headers in response can be exploited by the attacker to execute Cross-Site Scripting (XSS) attacks.
2021-06-09T14:15:08.247
2024-11-21T05:58:18.180
Modified
CVSSv3.1: 5.4 (MEDIUM)
AV:N/AC:M/Au:S/C:N/I:P/A:N
6.8
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | sap | manufacturing_execution | 15.1 | Yes |
| Application | sap | manufacturing_execution | 15.2 | Yes |
| Application | sap | manufacturing_execution | 15.3 | Yes |
| Application | sap | manufacturing_execution | 15.4 | Yes |