4.3
CVSSv2

CVE-2017-6061

Published: 16/03/2017 Updated: 16/03/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 4.7 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the help component of SAP BusinessObjects Financial Consolidation 10.0.0.1933 allows remote malicious users to inject arbitrary web script or HTML via a GET request. /finance/help/en/frameset.htm is the URI for this component. The vendor response is SAP Security Note 2368106.

Vulnerable Product Search on Vulmon Subscribe to Product

sap businessobjects financial consolidation 10.0.0.1933

Exploits

SAP BusinessObjects Financial Consolidation version 10001933 suffers from a cross site scripting vulnerability in the help component ...