CVE-2017-15294: XSS
Published Oct 16, 2017
·Updated
The Java administration console in SAP CRM has XSS. This is SAP Security Note 2478964.
Affected Software
8 affected components
SAP Customer Relationship Management=700
SAP Customer Relationship Management=701
SAP Customer Relationship Management=702
SAP Customer Relationship Management=730
SAP Customer Relationship Management=731
SAP Customer Relationship Management=732
SAP Customer Relationship Management=733
SAP Customer Relationship Management=754
Event History
Oct 16, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-15294?
CVE-2017-15294 has been classified as a moderate severity vulnerability due to the potential for cross-site scripting (XSS) attacks.
2
How do I fix CVE-2017-15294?
To address CVE-2017-15294, apply the patches provided in SAP Security Note 2478964 to the affected versions of SAP Customer Relationship Management.
3
Which versions of SAP CRM are affected by CVE-2017-15294?
CVE-2017-15294 affects SAP Customer Relationship Management versions 700, 701, 702, 730, 731, 732, 733, and 754.
4
What type of vulnerability is CVE-2017-15294?
CVE-2017-15294 is an XSS vulnerability within the Java administration console of SAP CRM.
5
Can CVE-2017-15294 be exploited without authentication?
Yes, CVE-2017-15294 can potentially be exploited by attackers without requiring authentication.