漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal
Vulnerability Description
Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal, an unauthenticated attacker could inject malicious scripts that execute in the context of other users� browsers, allowing the attacker to steal session cookies, tokens, and other sensitive information. As a result, the vulnerability has a low impact on confidentiality and integrity and no impact on availability.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Vulnerability Type
遗留的调试代码
Vulnerability Title
SAP NetWeaver Enterprise Portal 安全漏洞
Vulnerability Description
SAP NetWeaver Enterprise Portal是德国思爱普(SAP)公司的一个 SAP NetWeaver的 Web 前端组件。 SAP NetWeaver Enterprise Portal存在安全漏洞,该漏洞源于跨站脚本攻击可导致会话cookie和令牌等敏感信息泄露,对机密性和完整性影响较低。
CVSS Information
N/A
Vulnerability Type
N/A