First published: Wed Apr 16 2008(Updated: )
The default configuration of SAP NetWeaver before 7.0 SP15 does not enable the "Always Use Secure HTML Editor" (aka Editor Security or Secure Editing) parameter, which allows remote attackers to conduct cross-site scripting (XSS) attacks by entering feedback for a file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SAP NetWeaver | <=7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-1846 is considered a high severity vulnerability due to its potential for remote exploitation through cross-site scripting attacks.
To fix CVE-2008-1846, ensure that the "Always Use Secure HTML Editor" setting is enabled in the SAP NetWeaver configuration.
CVE-2008-1846 affects SAP NetWeaver versions prior to 7.0 SP15.
CVE-2008-1846 allows attackers to conduct cross-site scripting (XSS) attacks by exploiting the default configuration settings.
A temporary workaround for CVE-2008-1846 is to manually sanitize user input before it is rendered in the application.