PT-2018-15582 · Sap · Sap Data Services
Published
2018-10-09
·
Updated
2018-11-23
·
CVE-2018-2466
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
SAP Data Services version 4.2
Description
The management console in SAP Data Services does not sufficiently validate user-controlled inputs, resulting in a Cross-Site Scripting (XSS) issue.
Recommendations
For version 4.2, consider implementing additional input validation mechanisms to prevent Cross-Site Scripting attacks. As a temporary workaround, restrict access to the management console to minimize the risk of exploitation.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Data Services