PT-2008-3377 · Sap · Sap Netweaver
Jaime Blasco
·
Published
2008-04-16
·
Updated
2018-10-11
·
CVE-2008-1846
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
SAP NetWeaver versions prior to 7.0 SP15
Description
The issue concerns the default configuration of SAP NetWeaver, where the "Always Use Secure HTML Editor" parameter is not enabled, allowing remote attackers to conduct cross-site scripting (XSS) attacks by entering feedback for a file.
Recommendations
For SAP NetWeaver versions prior to 7.0 SP15, enable the "Always Use Secure HTML Editor" parameter to prevent cross-site scripting attacks.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Netweaver