PT-2008-3377 · Sap · Sap Netweaver

Jaime Blasco

·

Published

2008-04-16

·

Updated

2018-10-11

·

CVE-2008-1846

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions SAP NetWeaver versions prior to 7.0 SP15
Description The issue concerns the default configuration of SAP NetWeaver, where the "Always Use Secure HTML Editor" parameter is not enabled, allowing remote attackers to conduct cross-site scripting (XSS) attacks by entering feedback for a file.
Recommendations For SAP NetWeaver versions prior to 7.0 SP15, enable the "Always Use Secure HTML Editor" parameter to prevent cross-site scripting attacks.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-1846

Affected Products

Sap Netweaver