CVE-2009-2932: XSS
Published Aug 21, 2009
·Updated
Cross-site scripting (XSS) vulnerability in uddiclient/process in the UDDI client in SAP NetWeaver Application Server (Java) 7.0 allows remote attackers to inject arbitrary web script or HTML via the TModel Key field.
Affected Software
1 affected component
SAP NetWeaver=7.0
Event History
Aug 21, 2009
CVE Published
via MITRE·08:21 PM
Data Sourced
via MITRE·08:21 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-2932?
CVE-2009-2932 is classified as a moderate severity cross-site scripting (XSS) vulnerability.
2
How can I mitigate CVE-2009-2932?
To mitigate CVE-2009-2932, ensure that input validation and proper output encoding are implemented in the affected application.
3
What versions of SAP NetWeaver are affected by CVE-2009-2932?
CVE-2009-2932 specifically affects SAP NetWeaver Application Server (Java) version 7.0.
4
What type of attack can exploit CVE-2009-2932?
CVE-2009-2932 can be exploited by attackers to inject arbitrary web scripts or HTML through the TModel Key field.
5
Are there any known exploits for CVE-2009-2932?
Yes, there are known exploits for CVE-2009-2932 that allow attackers to carry out XSS attacks.