4.3

CVE-2007-3496

Cross-site scripting (XSS) vulnerability in SAP Web Dynpro Java (BC-WD-JAV) in SAP NetWeaver Nw04 SP15 through SP19 and Nw04s SP7 through SP11, aka SAP Java Technology Services 640 before SP20 and SAP Web Dynpro Runtime Core Components 700 before SP12, allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SAPNetweaver Nw04 Versionsp15
SAPNetweaver Nw04 Versionsp16
SAPNetweaver Nw04 Versionsp17
SAPNetweaver Nw04 Versionsp18
SAPNetweaver Nw04 Versionsp19
SAPNetweaver Nw04s Versionsp7
SAPNetweaver Nw04s Versionsp8
SAPNetweaver Nw04s Versionsp9
SAPNetweaver Nw04s Versionsp10
SAPNetweaver Nw04s Versionsp11
SAPSap Basis Component 640 Version <= sp19
SAPSap Basis Component 700 Version <= sp11
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.59% 0.682
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N