First published: Thu Oct 16 2014(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in SAP HANA Developer Edition Revision 70 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to (1) epm/admin/DataGen.xsjs or (2) epm/services/multiply.xsjs in the democontent.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SAP HANA Database |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-8314 is classified as a medium severity vulnerability due to its potential to facilitate cross-site scripting attacks.
To remediate CVE-2014-8314, ensure that SAP HANA Developer Edition is updated to a version that includes patches addressing these XSS vulnerabilities.
CVE-2014-8314 can enable remote attackers to inject arbitrary web script or HTML, potentially leading to data theft or session hijacking.
CVE-2014-8314 specifically affects the epm/admin/DataGen.xsjs and epm/services/multiply.xsjs components in SAP HANA Developer Edition.
CVE-2014-8314 should not be a threat if SAP HANA Developer Edition is kept up to date with the latest security patches.