First published: Thu Feb 23 2012(Updated: )
Cross-site scripting (XSS) vulnerability in b2b/auction/container.jsp in the Internet Sales (crm.b2b) module in SAP NetWeaver 7.0 allows remote attackers to inject arbitrary web script or HTML via the _loadPage parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SAP NetWeaver | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2012-1290 is classified as medium due to its potential for exploitation via cross-site scripting.
To fix CVE-2012-1290, ensure to apply the latest security patches released by SAP for NetWeaver 7.0.
CVE-2012-1290 affects SAP NetWeaver version 7.0.
CVE-2012-1290 is a cross-site scripting (XSS) vulnerability that allows injection of arbitrary web scripts.
By exploiting CVE-2012-1290, attackers can execute malicious scripts in the context of the user's browser.