ID

VAR-201007-0348


TITLE

SAP NetWeaver System Landscape Catalog Component Cross-Site Scripting Vulnerability

Trust: 0.6

sources: CNVD: CNVD-2010-1445

DESCRIPTION

SAP NetWeaver is the technical foundation for SAP Business Suite solutions, SAP xApps composite applications, partner solutions, and custom applications. SAP NetWeaver has input validation errors that can be exploited by remote attackers for cross-site scripting attacks. Inputs passed to testsdic via the \"action\" parameter and passed to paramhelp.jsp via the \"helpstring\" parameter in the System Landscape directory component are not filtered before returning to the user, and the attacker can exploit the vulnerability to gain sensitive information or hijack the target user session

Trust: 0.72

sources: CNVD: CNVD-2010-1445 // IVD: ce3cb788-1fb2-11e6-abef-000c29c66e3d

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.8

sources: IVD: ce3cb788-1fb2-11e6-abef-000c29c66e3d // CNVD: CNVD-2010-1445

AFFECTED PRODUCTS

vendor:sapmodel:web application serverscope:eqversion:6.x

Trust: 0.8

vendor:sapmodel:netweaverscope:eqversion:7.x

Trust: 0.6

vendor:sapmodel:netweaverscope:eqversion:4.x(2004)

Trust: 0.6

vendor:sapmodel:enterprise portalscope:eqversion:6.x

Trust: 0.6

vendor:sapmodel:web application serverscope:eqversion:7.x

Trust: 0.6

vendor:sapmodel:netweaverscope:eqversion:7.x*

Trust: 0.2

vendor:sapmodel:netweaverscope:eqversion:4.x(2004)*

Trust: 0.2

vendor:sapmodel:enterprise portalscope:eqversion:6.x*

Trust: 0.2

vendor:sapmodel:web application serverscope:eqversion:7.x*

Trust: 0.2

sources: IVD: ce3cb788-1fb2-11e6-abef-000c29c66e3d // CNVD: CNVD-2010-1445

CVSS

SEVERITY

CVSSV2

CVSSV3

IVD: ce3cb788-1fb2-11e6-abef-000c29c66e3d
value: LOW

Trust: 0.2

IVD: ce3cb788-1fb2-11e6-abef-000c29c66e3d
severity: NONE
baseScore: NONE
vectorString: NONE
accessVector: NONE
accessComplexity: NONE
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: UNKNOWN

Trust: 0.2

sources: IVD: ce3cb788-1fb2-11e6-abef-000c29c66e3d

TYPE

Cross-site scripting

Trust: 0.2

sources: IVD: ce3cb788-1fb2-11e6-abef-000c29c66e3d

EXTERNAL IDS

db:CNVDid:CNVD-2010-1445

Trust: 0.8

db:IVDid:CE3CB788-1FB2-11E6-ABEF-000C29C66E3D

Trust: 0.2

sources: IVD: ce3cb788-1fb2-11e6-abef-000c29c66e3d // CNVD: CNVD-2010-1445

REFERENCES

url:http://dsecrg.com/pages/vul/show.php?id=168http

Trust: 0.6

sources: CNVD: CNVD-2010-1445

SOURCES

db:IVDid:ce3cb788-1fb2-11e6-abef-000c29c66e3d
db:CNVDid:CNVD-2010-1445

LAST UPDATE DATE

2022-05-17T01:46:48.506000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2010-1445date:2010-07-29T00:00:00

SOURCES RELEASE DATE

db:IVDid:ce3cb788-1fb2-11e6-abef-000c29c66e3ddate:2010-07-29T00:00:00
db:CNVDid:CNVD-2010-1445date:2010-07-29T00:00:00