Multiple XSS Vulnerabilities in SAP NetWeaver Business Client
CVE-2014-4160

Currently unrated

Key Information:

Vendor
SAP
Vendor
CVE Published:
13 June 2014

Summary

The SAP NetWeaver Business Client contains multiple cross-site scripting vulnerabilities within the testcanvas node. These flaws enable remote attackers to execute arbitrary web scripts or HTML by exploiting the title or sap-accessibility parameters, potentially compromising user data and application integrity. Proper input validation and output encoding measures are crucial to mitigate such risks and secure web applications effectively.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.