CVE-2010-3981: XSS
Published Oct 18, 2010
·Updated
Cross-site scripting (XSS) vulnerability in SAP BusinessObjects Enterprise XI 3.2 allows remote attackers to inject arbitrary web script or HTML via the ServiceClass field to the Edit Service Parameters page.
Affected Software
1 affected component
SAP BusinessObjects=3.2
Event History
Oct 18, 2010
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-3981?
The severity of CVE-2010-3981 is classified as medium, indicating a moderate risk to affected systems.
2
How do I fix CVE-2010-3981?
To fix CVE-2010-3981, you should apply the latest security patches provided by SAP for BusinessObjects Enterprise XI 3.2.
3
What types of attacks are possible due to CVE-2010-3981?
CVE-2010-3981 could allow remote attackers to perform cross-site scripting (XSS) attacks by injecting malicious scripts.
4
Which versions of SAP BusinessObjects are affected by CVE-2010-3981?
CVE-2010-3981 specifically affects SAP BusinessObjects Enterprise XI version 3.2.
5
Can CVE-2010-3981 be exploited without user interaction?
Yes, CVE-2010-3981 can be exploited remotely without requiring any user interaction.