First published: Thu Jul 31 2014(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in the XS Administration Tools in SAP HANA allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SAP HANA |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-5172 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2014-5172, it is recommended to apply the latest patches provided by SAP for the HANA platform.
CVE-2014-5172 may allow attackers to execute arbitrary scripts in the context of the user's session via cross-site scripting.
CVE-2014-5172 affects the XS Administration Tools in SAP HANA.
CVE-2014-5172 was disclosed in July 2014.