CVE-2010-1609: XSS
Published Apr 29, 2010
·Updated
Cross-site scripting (XSS) vulnerability in SAP NetWeaver 2004 before SP21 and 2004s before SP13 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
2 affected components
SAP NetWeaver=4.0
SAP NetWeaver=7.0
Remediation
Patch Available
Event History
Apr 29, 2010
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
via NVD·05:30 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2010-1609?
CVE-2010-1609 is classified as a medium severity vulnerability.
2
How do I fix CVE-2010-1609?
To fix CVE-2010-1609, you should upgrade SAP NetWeaver to version SP21 or later for version 2004 or SP13 or later for version 2004s.
3
What types of systems are affected by CVE-2010-1609?
CVE-2010-1609 affects SAP NetWeaver versions 4.0 and 7.0 prior to specific service pack releases.
4
What impact does CVE-2010-1609 have on my system?
CVE-2010-1609 allows remote attackers to execute arbitrary web scripts or HTML, potentially leading to data theft or site defacement.
5
Are there any known exploits for CVE-2010-1609?
Yes, there are known exploits that take advantage of the CVE-2010-1609 vulnerability, targeting its cross-site scripting capability.