CVE-2014-1965: XSS
Cross-site scripting (XSS) vulnerability in ISpeakAdapter in the Integration Repository in the SAP Exchange Infrastructure (BC-XI) component 3.0, 7.00 through 7.02, and 7.10 through 7.11 for SAP NetWeaver allows remote attackers to inject arbitrary web script or HTML via vectors related to PIP.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-1965?
CVE-2014-1965 has a medium severity rating due to its potential for exploitation through cross-site scripting.
How do I fix CVE-2014-1965?
To fix CVE-2014-1965, apply the latest patches or updates provided by SAP for the affected versions of NetWeaver.
What components are affected by CVE-2014-1965?
CVE-2014-1965 affects the ISpeakAdapter in the Integration Repository of the SAP Exchange Infrastructure.
Can CVE-2014-1965 be exploited remotely?
Yes, CVE-2014-1965 can be exploited remotely by attackers injecting arbitrary web scripts or HTML.
What versions of SAP NetWeaver are impacted by CVE-2014-1965?
CVE-2014-1965 impacts SAP NetWeaver versions 3.0, 7.0, 7.01, 7.02, 7.10, and 7.11.