CVE Vulnerabilities

CVE-2007-3496

Published: Jun 29, 2007 | Modified: Oct 16, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Cross-site scripting (XSS) vulnerability in SAP Web Dynpro Java (BC-WD-JAV) in SAP NetWeaver Nw04 SP15 through SP19 and Nw04s SP7 through SP11, aka SAP Java Technology Services 640 before SP20 and SAP Web Dynpro Runtime Core Components 700 before SP12, allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header.

Affected Software

Name Vendor Start Version End Version
Netweaver_nw04 Sap sp19 sp19
Sap_basis_component_700 Sap * sp11
Netweaver_nw04 Sap sp16 sp16
Netweaver_nw04s Sap sp8 sp8
Netweaver_nw04s Sap sp9 sp9
Netweaver_nw04s Sap sp7 sp7
Netweaver_nw04 Sap sp18 sp18
Sap_basis_component_640 Sap * sp19
Netweaver_nw04 Sap sp15 sp15
Netweaver_nw04s Sap sp11 sp11
Netweaver_nw04 Sap sp17 sp17
Netweaver_nw04s Sap sp10 sp10

References