Cross-Site Scripting Vulnerability in SAP Afaria 7
CVE-2015-6663

Currently unrated

Key Information:

Vendor
SAP
Status
Vendor
CVE Published:
24 August 2015

Summary

A cross-site scripting (XSS) vulnerability exists in the Client form on the Device Inspector page of SAP Afaria 7. This flaw enables remote attackers to inject malicious web scripts or HTML code via specially crafted client name data. Exploiting this vulnerability can compromise user security, allowing attackers to potentially hijack user sessions or execute unauthorized actions within the application. Security practitioners should take immediate action to safeguard against this vulnerability by implementing the appropriate security patches and configurations.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.