First published: Thu Apr 29 2010(Updated: )
Cross-site scripting (XSS) vulnerability in SAP NetWeaver 2004 before SP21 and 2004s before SP13 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SAP NetWeaver | =4.0 | |
SAP NetWeaver | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-1609 is classified as a medium severity vulnerability.
To fix CVE-2010-1609, you should upgrade SAP NetWeaver to version SP21 or later for version 2004 or SP13 or later for version 2004s.
CVE-2010-1609 affects SAP NetWeaver versions 4.0 and 7.0 prior to specific service pack releases.
CVE-2010-1609 allows remote attackers to execute arbitrary web scripts or HTML, potentially leading to data theft or site defacement.
Yes, there are known exploits that take advantage of the CVE-2010-1609 vulnerability, targeting its cross-site scripting capability.