CVE-2018-17862: XSS
UNSUPPORTED WHEN ASSIGNED A cross-site scripting (XSS) vulnerability in SAP J2EE Engine/7.01/Fiori allows remote attackers to inject arbitrary web script via the sysjdbc parameter to /TestJDBCWeb/test2. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-17862?
CVE-2018-17862 is a cross-site scripting (XSS) vulnerability in SAP J2EE Engine/7.01/Fiori that allows remote attackers to inject arbitrary web script.
How severe is CVE-2018-17862?
CVE-2018-17862 has a severity value of 6.1, which is considered medium.
What software is affected by CVE-2018-17862?
SAP J2EE Engine version 7.01 is affected by CVE-2018-17862.
How can CVE-2018-17862 be exploited?
CVE-2018-17862 can be exploited by remote attackers injecting arbitrary web script through the sys_jdbc parameter to /TestJDBC_Web/test2.
Are there any references related to CVE-2018-17862?
Yes, you can find more information about CVE-2018-17862 at the following URLs: [URL1], [URL2], [URL3].