CVE-2012-1290: XSS
Published Feb 23, 2012
·Updated
Cross-site scripting (XSS) vulnerability in b2b/auction/container.jsp in the Internet Sales (crm.b2b) module in SAP NetWeaver 7.0 allows remote attackers to inject arbitrary web script or HTML via the loadPage parameter.
Affected Software
1 affected component
SAP NetWeaver=7.0
Event History
Feb 23, 2012
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-1290?
The severity of CVE-2012-1290 is classified as medium due to its potential for exploitation via cross-site scripting.
2
How do I fix CVE-2012-1290?
To fix CVE-2012-1290, ensure to apply the latest security patches released by SAP for NetWeaver 7.0.
3
What software is affected by CVE-2012-1290?
CVE-2012-1290 affects SAP NetWeaver version 7.0.
4
What type of vulnerability is CVE-2012-1290?
CVE-2012-1290 is a cross-site scripting (XSS) vulnerability that allows injection of arbitrary web scripts.
5
What can attackers achieve by exploiting CVE-2012-1290?
By exploiting CVE-2012-1290, attackers can execute malicious scripts in the context of the user's browser.