Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Cross Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal
Vulnerability Description
SAP NetWeaver Enterprise Portal allows an unauthenticated attacker to inject malicious scripts into a URL parameter. The scripts are reflected in the server response and executed in a user's browser when the crafted URL is visited, leading to theft of session information, manipulation of portal content, or user redirection, resulting in a low impact on the application's confidentiality and integrity, with no impact on availability.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
SAP NetWeaver Enterprise Portal 跨站脚本漏洞
Vulnerability Description
SAP NetWeaver Enterprise Portal是德国SAP公司的一个 SAP NetWeaver的 Web 前端组件。 SAP NetWeaver Enterprise Portal EP-RUNTIME 7.50版本存在跨站脚本漏洞,该漏洞源于允许未经验证的攻击者向URL参数注入恶意脚本,这些脚本被反射回服务器响应中,在用户访问特制URL时在浏览器中执行,导致会话信息窃取、门户内容操纵或用户重定向,对应用的机密性和完整性造成低影响,对可用性无影响。
CVSS Information
N/A
Vulnerability Type
N/A