First published: Mon Aug 09 2021(Updated: )
** UNSUPPORTED WHEN ASSIGNED ** A cross-site scripting (XSS) vulnerability in SAP J2EE Engine 7.01 allows remote attackers to inject arbitrary web script via the wsdlPath parameter to /ctcprotocol/Protocol. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SAP J2EE Engine | =7.01 | |
=7.01 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2018-17865.
The severity level of CVE-2018-17865 is medium, with a CVSS score of 6.1.
The CVE-2018-17865 vulnerability occurs due to a cross-site scripting (XSS) vulnerability in the SAP J2EE Engine 7.01, allowing remote attackers to inject arbitrary web script.
The CVE-2018-17865 vulnerability can be exploited by sending malicious input as the wsdlPath parameter to /ctcprotocol/Protocol.
Since the vulnerability affects products that are no longer supported by the maintainer, there might not be an official fix available. However, it is recommended to implement mitigations, such as input validation and output encoding, to prevent exploitation of the vulnerability.