CVE-2014-5172: XSS
Published Jul 31, 2014
·Updated
Multiple cross-site scripting (XSS) vulnerabilities in the XS Administration Tools in SAP HANA allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
1 affected component
SAP HANA
Event History
Jul 31, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-5172?
CVE-2014-5172 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2014-5172?
To fix CVE-2014-5172, it is recommended to apply the latest patches provided by SAP for the HANA platform.
3
What types of attacks are possible with CVE-2014-5172?
CVE-2014-5172 may allow attackers to execute arbitrary scripts in the context of the user's session via cross-site scripting.
4
Which software is affected by CVE-2014-5172?
CVE-2014-5172 affects the XS Administration Tools in SAP HANA.
5
When was CVE-2014-5172 disclosed?
CVE-2014-5172 was disclosed in July 2014.