SAP NetWeaver - versions 700, 701, 702, 730, does not sufficiently encode user-controlled inputs, allowing an attacker to cause a potential victim to supply a malicious content to a vulnerable web application, which is then reflected to the victim and executed by the web browser, resulting in Cross-Site Scripting vulnerability.
2021-10-12T15:15:08.993
2024-11-21T06:16:35.350
Modified
CVSSv3.1: 6.1 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:P/A:N
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | sap | netweaver | 700 | Yes |
Application | sap | netweaver | 701 | Yes |
Application | sap | netweaver | 702 | Yes |
Application | sap | netweaver | 730 | Yes |