Multiple Cross-Site Scripting Vulnerabilities in SAP Web Application Server by SAP
CVE-2005-3635

Currently unrated

Key Information:

Vendor

SAP

Vendor
CVE Published:
16 November 2005

What is CVE-2005-3635?

The SAP Web Application Server versions 6.10 to 7.00 contain multiple cross-site scripting vulnerabilities that enable remote attackers to inject arbitrary web scripts or HTML into web pages. Exploiting these flaws involves manipulating inputs such as the 'sap-syscmd' command and the 'BspApplication' field in the SYSTEM PUBLIC test application, potentially compromising sensitive user data and enabling further attacks.

References

EPSS Score

16% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.