Описание
SAP NetWeaver Application Server Java allows an unauthenticated attacker to inject malicious JavaScript through crafted URLs. When a victim accesses such a URL, the script executes in the user's browser, allowing the attacker to access sensitive session information and modify non-sensitive data displayed in the client�s browser. This results in a high impact on confidentiality, low impact on integrity with no impact on availability of the application.
EPSS
8.2 High
CVSS3
Дефекты
Связанные уязвимости
SAP NetWeaver Application Server Java allows an unauthenticated attacker to inject malicious JavaScript through crafted URLs. When a victim accesses such a URL, the script executes in the user's browser, allowing the attacker to access sensitive session information and modify non-sensitive data displayed in the client�s browser. This results in a high impact on confidentiality, low impact on integrity with no impact on availability of the application.
Уязвимость веб-интерфейса Configuration Wizard сервера приложений SAP NetWeaver Application Server Java, позволяющая нарушителю проводить межсайтовые сценарные атаки
EPSS
8.2 High
CVSS3