A vulnerability in SAP NW EP (WPC) - versions 7.30, 7.31, 7.40, 7.50, which does not sufficiently validate user-controlled input, allows a remote malicious user to conduct a Cross-Site (XSS) scripting attack. A successful exploit could allow the malicious user to execute arbitrary script code which could lead to stealing or modifying of authentication information of the user, such as data relating to his or her current session.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
sap netweaver enterprise portal 7.31 |
||
sap netweaver enterprise portal 7.30 |
||
sap netweaver enterprise portal 7.40 |
||
sap netweaver enterprise portal 7.50 |