vendor:
SAP Netweaver
by:
Unknown
7.5
CVSS
HIGH
Cross-Site Scripting (XSS)
79
CWE
Product Name: SAP Netweaver
Affected Version From: 6.4
Affected Version To: 7
Patch Exists: No
Related CWE: Not mentioned
CPE: a:sap:netweaver:6.4, cpe:/a:sap:netweaver:7.0
Platforms Tested: Unknown
Unknown
Cross-Site Scripting Vulnerability in SAP Netweaver
The vulnerability exists in SAP Netweaver due to improper input sanitization. An attacker can exploit this vulnerability to execute arbitrary script code in the browser of a user visiting the affected site. This can lead to the theft of authentication credentials and other malicious activities.
Mitigation:
Apply patches or updates provided by the vendor to address the vulnerability. Implement strict input validation and output encoding to prevent XSS attacks.