4.3
CVSSv2

CVE-2010-2904

Published: 28/07/2010 Updated: 17/08/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in the System Landscape Directory (SLD) component 6.4 up to and including 7.02 in SAP NetWeaver allow remote malicious users to inject arbitrary web script or HTML via the (1) action parameter to testsdic and the (2) helpstring parameter to paramhelp.jsp.

Vulnerable Product Search on Vulmon Subscribe to Product

sap system_landscape_directory 6.4

sap system_landscape_directory 7.0

sap system_landscape_directory 7.02

sap netweaver

sap netweaver 6.4

sap netweaver 7.0