CVE-2017-10701 Information

Description

Cross site scripting (XSS) vulnerability in SAP Enterprise Portal 7.50 allows remote attackers to inject arbitrary web script or HTML aka SAP Security Notes 2469860 2471209 and 2488516.

CVSS Vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Reference

http://www.securityfocus.com/bid/100786 http://www.securityfocus.com/bid/100788 http://www.securityfocus.com/bid/100805 http://www.securityfocus.com/bid/101068 https://cxsecurity.com/issue/WLB-2017090219

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

REQUIRED

Confidentiality Impact

CHANGED

Integrity Impact

LOW

Availability Impact

LOW

Base Score

NONE

Base Severity

6.1

Share on: