CVE-2014-1964: XSS
Cross-site scripting (XSS) vulnerability in the Integration Repository in the SAP Exchange Infrastructure (BC-XI) component in SAP NetWeaver allows remote attackers to inject arbitrary web script or HTML via vectors related to the ESR application and a DIR error.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-1964?
CVE-2014-1964 is classified as a medium severity vulnerability.
How do I fix CVE-2014-1964?
To fix CVE-2014-1964, ensure that your SAP NetWeaver and Exchange Infrastructure are updated to the latest supported versions that contain security patches for this vulnerability.
What components are affected by CVE-2014-1964?
CVE-2014-1964 affects the Integration Repository in the SAP Exchange Infrastructure and the SAP NetWeaver platform.
What type of vulnerability is CVE-2014-1964?
CVE-2014-1964 is a Cross-site scripting (XSS) vulnerability.
Can CVE-2014-1964 be exploited remotely?
Yes, CVE-2014-1964 can be exploited remotely allowing attackers to inject arbitrary web scripts or HTML.