First published: Tue Jul 25 2017(Updated: )
Cross-site scripting (XSS) vulnerability in the ctcprotocol/Protocol servlet in SAP NetWeaver AS JAVA 7.3 allows remote attackers to inject arbitrary web script or HTML via the sessionID parameter, aka SAP Security Note 2406783.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SAP NetWeaver Java Application Server | =7.30 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-11458 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
CVE-2017-11458 affects SAP NetWeaver AS JAVA 7.3 by allowing remote attackers to inject arbitrary web scripts via the sessionID parameter.
To fix CVE-2017-11458, apply the patches provided in SAP Security Note 2406783.
Organizations using SAP NetWeaver AS JAVA version 7.3 are affected by CVE-2017-11458.
CVE-2017-11458 can facilitate cross-site scripting (XSS) attacks, allowing the injection of malicious scripts.