4.3
CVSSv2

CVE-2007-3496

Published: 29/06/2007 Updated: 16/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in SAP Web Dynpro Java (BC-WD-JAV) in SAP NetWeaver Nw04 SP15 through SP19 and Nw04s SP7 through SP11, aka SAP Java Technology Services 640 before SP20 and SAP Web Dynpro Runtime Core Components 700 before SP12, allows remote malicious users to inject arbitrary web script or HTML via the User-Agent HTTP header.

Vulnerable Product Search on Vulmon Subscribe to Product

sap netweaver nw04 sp17

sap netweaver nw04 sp18

sap sap basis component 640

sap sap basis component 700

sap netweaver nw04s sp11

sap netweaver nw04s sp7

sap netweaver nw04 sp19

sap netweaver nw04s sp10

sap netweaver nw04 sp15

sap netweaver nw04 sp16

sap netweaver nw04s sp8

sap netweaver nw04s sp9