First published: Fri Jun 29 2007(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in the SAP Internet Communication Framework (BC-MID-ICF) in the SAP Basis component 700 before SP12, and 640 before SP20, allow remote attackers to inject arbitrary web script or HTML via certain parameters associated with the default login error page.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sap Sap Basis Component 700 | <=sp11 | |
Sap Sap Basis Component 640 | <=sp19 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-3495 has a medium severity due to its potential to allow remote attackers to execute cross-site scripting attacks.
To fix CVE-2007-3495, upgrade to SAP Basis component 700 Service Pack 12 or higher, or 640 Service Pack 20 or higher.
CVE-2007-3495 affects SAP Basis component 700 versions prior to SP12 and 640 versions prior to SP20.
Yes, CVE-2007-3495 can affect web applications that utilize the vulnerable versions of SAP Basis components, leading to potential XSS vulnerabilities.
Failing to address CVE-2007-3495 may result in unauthorized script execution on the affected applications, compromising user data and the integrity of the application.