CVE-2017-6061: XSS
Cross-site scripting (XSS) vulnerability in the help component of SAP BusinessObjects Financial Consolidation 10.0.0.1933 allows remote attackers to inject arbitrary web script or HTML via a GET request. /finance/help/en/frameset.htm is the URI for this component. The vendor response is SAP Security Note 2368106.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6061?
CVE-2017-6061 has been classified as a medium severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2017-6061?
To fix CVE-2017-6061, update SAP BusinessObjects Financial Consolidation to the latest version that addresses this vulnerability.
What types of attacks can exploit CVE-2017-6061?
CVE-2017-6061 can be exploited by remote attackers to inject arbitrary web scripts or HTML into the affected application.
Which software is affected by CVE-2017-6061?
Only SAP BusinessObjects Financial Consolidation version 10.0.0.1933 is affected by CVE-2017-6061.
What is the impact of CVE-2017-6061 if exploited?
If exploited, CVE-2017-6061 can lead to unauthorized actions on behalf of users, potentially compromising sensitive information.