First published: Mon Oct 16 2017(Updated: )
The Java administration console in SAP CRM has XSS. This is SAP Security Note 2478964.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Customer Relationship Management | =700 | |
SAP Customer Relationship Management | =701 | |
SAP Customer Relationship Management | =702 | |
SAP Customer Relationship Management | =730 | |
SAP Customer Relationship Management | =731 | |
SAP Customer Relationship Management | =732 | |
SAP Customer Relationship Management | =733 | |
SAP Customer Relationship Management | =754 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-15294 has been classified as a moderate severity vulnerability due to the potential for cross-site scripting (XSS) attacks.
To address CVE-2017-15294, apply the patches provided in SAP Security Note 2478964 to the affected versions of SAP Customer Relationship Management.
CVE-2017-15294 affects SAP Customer Relationship Management versions 700, 701, 702, 730, 731, 732, 733, and 754.
CVE-2017-15294 is an XSS vulnerability within the Java administration console of SAP CRM.
Yes, CVE-2017-15294 can potentially be exploited by attackers without requiring authentication.