Cross-site scripting vulnerabilities in SAP Internet Communication Framework by SAP
CVE-2007-3495

Currently unrated

Key Information:

Vendor

SAP

Vendor
CVE Published:
29 June 2007

What is CVE-2007-3495?

The SAP Internet Communication Framework contains multiple cross-site scripting vulnerabilities that can be exploited by remote attackers. These vulnerabilities arise from improper handling of certain parameters associated with the default login error page, enabling attackers to inject arbitrary web scripts or HTML. This risk affects SAP Basis components prior to specific service packs, underscoring the importance of timely updates and security patching.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.