Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross-site scripting (XSS) vulnerability in the Web GUI in SAP Web Application Server (WAS) 7.0, Web Dynpro for ABAP (aka WD4A or WDA), and Web Dynpro for BSP allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI under bc/gui/sap/its/webgui/.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
SAP Web应用服务器远程跨站脚本漏洞
Vulnerability Description
SAP Web应用服务器可给企业用户带来更高的互操作性和灵活性,为产品增加额外的Web服务。 SAP Web应用服务实现上存在输入验证漏洞,如果远程攻击者向SAP Web应用服务器提交了恶意的/sap/bc/gui/sap/its/webgui/ URL请求的话,就可以执行跨站脚本攻击。
CVSS Information
N/A
Vulnerability Type
N/A