First published: Thu May 27 2010(Updated: )
Cross-site scripting (XSS) vulnerability in axis2-admin/axis2-admin/engagingglobally in the administration console in Apache Axis2/Java 1.4.1, 1.5.1, and possibly other versions, as used in SAP Business Objects 12, 3com IMC, and possibly other products, allows remote attackers to inject arbitrary web script or HTML via the modules parameter. NOTE: some of these details are obtained from third party information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache HTTP Server | =1.4.1 | |
Apache HTTP Server | =1.5.1 | |
3com Intelligent Management Center | ||
SAP BusinessObjects | =12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-2103 has a medium severity level due to its potential impact on web application security through cross-site scripting.
To fix CVE-2010-2103, it is recommended to upgrade Apache Axis2 to a version that is not vulnerable to XSS.
CVE-2010-2103 affects Apache Axis2 versions 1.4.1 and 1.5.1.
Yes, SAP Business Objects and 3com Intelligent Management Center may utilize vulnerable versions of Apache Axis2.
CVE-2010-2103 is classified as a cross-site scripting (XSS) vulnerability in the administration console of Apache Axis2.