4.3

CVE-2007-3496

Cross-site scripting (XSS) vulnerability in SAP Web Dynpro Java (BC-WD-JAV) in SAP NetWeaver Nw04 SP15 through SP19 and Nw04s SP7 through SP11, aka SAP Java Technology Services 640 before SP20 and SAP Web Dynpro Runtime Core Components 700 before SP12, allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SAP ≫ Netweaver Nw04 Version sp15
SAP ≫ Netweaver Nw04 Version sp16
SAP ≫ Netweaver Nw04 Version sp17
SAP ≫ Netweaver Nw04 Version sp18
SAP ≫ Netweaver Nw04 Version sp19
SAP ≫ Netweaver Nw04s Version sp7
SAP ≫ Netweaver Nw04s Version sp8
SAP ≫ Netweaver Nw04s Version sp9
SAP ≫ Netweaver Nw04s Version sp10
SAP ≫ Netweaver Nw04s Version sp11
SAP ≫ Sap Basis Component 640 Version <= sp19
SAP ≫ Sap Basis Component 700 Version <= sp11
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.87% 0.766
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/25866
http://www.vupen.com/english/advisories/2007/2381
http://osvdb.org/37748
http://securityreason.com/securityalert/2850
http://www.csnc.ch/advisory/sap01.html
http://www.securityfocus.com/archive/1/472341/100/0/threaded