Skip links
🔥🔥🔥 Join us for our upcoming training session at Black Hat MEA: "Securing SAP Systems: Expert Insights and Penetration Testing Techniques" 🛡️🔍

Security Note Cross Site scripting in System Info NWA, SAP security note 1169367

Description

System Info in NWA is not escaping some special characters.

Available fix and Supported packages

  • LM-CORE | 7.00 | 7.00
  • LM-CORE | 7.10 | 7.10
  • SAP-JEE | 6.40 | 6.40
  • SAP-JEE | 7.00 | 7.01

Affected component

    BC-JAS-ADM-ADM
    Administration

CVSS

Score: 0

Exploit

Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.

URL

https://launchpad.support.sap.com/#/notes/1169367

TAGS

#There-is-a-risk-of-cross-site-scripting-through-System-Info-in-NWA.

How to detect over 4100 vulnerabilities in SAP Systems?

More to explorer