Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Reflected Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP (Applications based on Business Server Pages)
Vulnerability Description
Due to a reflected cross-site scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP (Applications based on Business Server Pages), an unauthenticated attacker could craft a URL that exploits an unprotected URL parameter to embed a malicious script. If a victim clicks the link, the injected input is processed during web page generation, resulting in the execution of malicious content in the victim�s browser context. This could allow the attacker to access and/or modify information, impacting the confidentiality and integrity of the application, with no impact to availability.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
SAP NetWeaver Application Server ABAP 跨站脚本漏洞
Vulnerability Description
SAP NetWeaver Application Server ABAP是德国思爱普(SAP)公司的一个运行和开发基于ABAP语言的应用程序的平台。 SAP NetWeaver Application Server ABAP存在跨站脚本漏洞,该漏洞源于基于业务服务器页面的应用程序存在反射型跨站脚本,可能导致未经身份验证的攻击者通过特制URL嵌入恶意脚本,当受害者点击链接时,注入的输入在网页生成过程中被处理,导致恶意内容在受害者浏览器环境中执行,可能访问或修改信息,影响机密性和完整性。
CVSS Information
N/A
Vulnerability Type
N/A