CVE-2014-4161: XSS
Cross-site scripting (XSS) vulnerability in la/umTestSSO.jsp in SAP Supplier Relationship Management (SRM) allows remote attackers to inject arbitrary web script or HTML via the url parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4161?
CVE-2014-4161 is classified as a medium severity vulnerability.
How do I fix CVE-2014-4161?
To fix CVE-2014-4161, update to the latest version of SAP Supplier Relationship Management that has the vulnerability patched.
What are the potential impacts of CVE-2014-4161?
Exploitation of CVE-2014-4161 can lead to unauthorized access to sensitive information through cross-site scripting attacks.
Who is affected by CVE-2014-4161?
CVE-2014-4161 affects users of SAP Supplier Relationship Management who utilize the vulnerable la/umTestSSO.jsp component.
What is the nature of the vulnerability in CVE-2014-4161?
CVE-2014-4161 is a cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web scripts or HTML.