First published: Wed Jan 28 2009(Updated: )
Cross-site scripting (XSS) vulnerability in Web Dynpro (WD) in the SAP NetWeaver portal, when Internet Explorer 7.0.5730 is used, allows remote attackers to inject arbitrary web script or HTML via a crafted URI, which causes the XSS payload to be reflected in a text/plain document.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SAP NetWeaver | ||
Internet Explorer | =7.0.5730 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-3358 is categorized as a medium severity vulnerability due to its XSS nature allowing remote script execution.
To mitigate CVE-2008-3358, upgrade to a newer version of SAP NetWeaver that addresses this vulnerability.
CVE-2008-3358 affects SAP NetWeaver when accessed through Internet Explorer version 7.0.5730.
CVE-2008-3358 is a cross-site scripting (XSS) vulnerability that allows attackers to inject arbitrary web scripts.
Yes, CVE-2008-3358 can be exploited remotely by attackers crafting malicious URIs targeting the affected software.