Cross-site Scripting Vulnerability in SAP BusinessObjects Financial Consolidation
CVE-2017-6061
4.7MEDIUM
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 16 March 2017
What is CVE-2017-6061?
A cross-site scripting (XSS) vulnerability exists in the help component of SAP BusinessObjects Financial Consolidation 10.0.0.1933. This security issue permits remote attackers to inject arbitrary web scripts or HTML through a specially crafted GET request, particularly targeting the URI /finance/help/en/frameset.htm. The exploitation of this vulnerability could lead to significant security risks, compromising the integrity and confidentiality of user interactions within the application. The vendor has issued SAP Security Note 2368106 providing guidance on mitigating this vulnerability.