XSS Vulnerability in SAP Internet Transaction Server by SAP
CVE-2008-2123

Currently unrated

Key Information:

Vendor

SAP

Vendor
CVE Published:
9 May 2008

What is CVE-2008-2123?

A Cross-site scripting (XSS) vulnerability exists in the WGate component of SAP Internet Transaction Server (ITS) 6.20. This flaw enables remote attackers to manipulate web content by injecting arbitrary web scripts or HTML. The vulnerability can be exploited via a crafted '<>' sequence in the ~service parameter directed at wgate.dll or through specific Javascript splicing in the query string. This security issue highlights the need for enhanced web application security measures to prevent unauthorized script execution.

References

EPSS Score

18% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2008-2123 : XSS Vulnerability in SAP Internet Transaction Server by SAP