CVE-2011-5260: XSS
Published Feb 12, 2013
·Updated
Cross-site scripting (XSS) vulnerability in SAP/BW/DOC/METADATA in SAP NetWeaver allows remote attackers to inject arbitrary web script or HTML via the page parameter.
Affected Software
8 affected components
SAP NetWeaver=6.4
SAP NetWeaver=7.0-sp15
SAP NetWeaver=7.0-ehp2
SAP NetWeaver
SAP NetWeaver=4.0
SAP NetWeaver=7.0-ehp1
SAP NetWeaver=7.0-sp8
SAP NetWeaver=7.0
Event History
Feb 12, 2013
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-5260?
CVE-2011-5260 is rated as a high severity vulnerability due to its potential for remote exploitation via XSS attacks.
2
How do I fix CVE-2011-5260?
To fix CVE-2011-5260, it is recommended to apply the security patches provided by SAP for the affected versions of SAP NetWeaver.
3
What systems are affected by CVE-2011-5260?
CVE-2011-5260 affects multiple versions of SAP NetWeaver, including 4.0, 6.4, and various 7.0 releases.
4
What type of vulnerability is CVE-2011-5260?
CVE-2011-5260 is a cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts.
5
Can CVE-2011-5260 be exploited remotely?
Yes, CVE-2011-5260 can be exploited remotely by attackers using specially crafted requests to inject arbitrary web scripts.