First published: Fri Aug 21 2009(Updated: )
Cross-site scripting (XSS) vulnerability in uddiclient/process in the UDDI client in SAP NetWeaver Application Server (Java) 7.0 allows remote attackers to inject arbitrary web script or HTML via the TModel Key field.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SAP NetWeaver | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-2932 is classified as a moderate severity cross-site scripting (XSS) vulnerability.
To mitigate CVE-2009-2932, ensure that input validation and proper output encoding are implemented in the affected application.
CVE-2009-2932 specifically affects SAP NetWeaver Application Server (Java) version 7.0.
CVE-2009-2932 can be exploited by attackers to inject arbitrary web scripts or HTML through the TModel Key field.
Yes, there are known exploits for CVE-2009-2932 that allow attackers to carry out XSS attacks.