First published: Wed Jan 28 2009(Updated: )
Cross-site scripting (XSS) vulnerability in Web Dynpro (WD) in the SAP NetWeaver portal, when Internet Explorer 7.0.5730 is used, allows remote attackers to inject arbitrary web script or HTML via a crafted URI, which causes the XSS payload to be reflected in a text/plain document.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SAP NetWeaver | ||
Microsoft Internet Explorer | =7.0.5730 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.