CVE Vulnerabilities

CVE-2007-3496

Published: Jun 29, 2007 | Modified: Oct 16, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Cross-site scripting (XSS) vulnerability in SAP Web Dynpro Java (BC-WD-JAV) in SAP NetWeaver Nw04 SP15 through SP19 and Nw04s SP7 through SP11, aka SAP Java Technology Services 640 before SP20 and SAP Web Dynpro Runtime Core Components 700 before SP12, allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header.

Affected Software

Name Vendor Start Version End Version
Netweaver_nw04 Sap sp15 (including) sp15 (including)
Netweaver_nw04 Sap sp16 (including) sp16 (including)
Netweaver_nw04 Sap sp17 (including) sp17 (including)
Netweaver_nw04 Sap sp18 (including) sp18 (including)
Netweaver_nw04 Sap sp19 (including) sp19 (including)
Netweaver_nw04s Sap sp7 (including) sp7 (including)
Netweaver_nw04s Sap sp8 (including) sp8 (including)
Netweaver_nw04s Sap sp9 (including) sp9 (including)
Netweaver_nw04s Sap sp10 (including) sp10 (including)
Netweaver_nw04s Sap sp11 (including) sp11 (including)
Sap_basis_component_640 Sap * sp19 (including)
Sap_basis_component_700 Sap * sp11 (including)

References