Логотип exploitDog
bind:CVE-2018-2502
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2018-2502

Количество 2

Количество 2

nvd логотип

CVE-2018-2502

около 7 лет назад

TRACE method is enabled in SAP Business One Service Layer . Attacker can use XST (Cross Site Tracing) attack if frontend applications that are using Service Layer has a XSS vulnerability. This has been fixed in SAP Business One Service Layer (B1_ON_HANA, versions 9.2, 9.3).

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-hjc3-4rh8-3fpv

больше 3 лет назад

TRACE method is enabled in SAP Business One Service Layer . Attacker can use XST (Cross Site Tracing) attack if frontend applications that are using Service Layer has a XSS vulnerability. This has been fixed in SAP Business One Service Layer (B1_ON_HANA, versions 9.2, 9.3).

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2018-2502

TRACE method is enabled in SAP Business One Service Layer . Attacker can use XST (Cross Site Tracing) attack if frontend applications that are using Service Layer has a XSS vulnerability. This has been fixed in SAP Business One Service Layer (B1_ON_HANA, versions 9.2, 9.3).

CVSS3: 6.1
0%
Низкий
около 7 лет назад
github логотип
GHSA-hjc3-4rh8-3fpv

TRACE method is enabled in SAP Business One Service Layer . Attacker can use XST (Cross Site Tracing) attack if frontend applications that are using Service Layer has a XSS vulnerability. This has been fixed in SAP Business One Service Layer (B1_ON_HANA, versions 9.2, 9.3).

CVSS3: 6.1
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу