Description
SAP NetWeaver Application Server ABAP (Applications based on SAP GUI for HTML), versions - KRNL64NUC - 7.49, KRNL64UC - 7.49,7.53, KERNEL - 7.49,7.53,7.77,7.81,7.84, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
Related CPE's
a
sap
netweaver_application_server_abap
8
References
https://launchpad.support.sap.com/#/notes/3028370
Permissions RequiredVendor Advisory
https://launchpad.support.sap.com/#/notes/3028370
Permissions RequiredVendor Advisory
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
5.4 · Medium
Information
Source identifier
Vulnerability status
Modified
Published
2021-06-09T12:15:10.077Z
4 years agoLast modified
2024-11-21T05:09:18.870Z
1 year ago