CVE-2018-2371: XSS
The SAML 2.0 service provider of SAP Netweaver AS Java Web Application, 7.50, does not sufficiently encode user controlled inputs, which results in Cross-Site Scripting (XSS) vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-2371?
CVE-2018-2371 is classified with a medium severity rating due to the potential for Cross-Site Scripting (XSS) exploitation.
How do I fix CVE-2018-2371?
To fix CVE-2018-2371, update the SAP Netweaver AS Java Web Application to the latest patched version that addresses the XSS vulnerability.
What are the potential impacts of CVE-2018-2371?
The impacts of CVE-2018-2371 can include unauthorized actions performed by users on behalf of others, data theft, and session hijacking.
Which software is affected by CVE-2018-2371?
CVE-2018-2371 specifically affects the SAP Netweaver AS Java Web Application version 7.50.
Is user data at risk due to CVE-2018-2371?
Yes, user data can be at risk as CVE-2018-2371 allows attackers to inject malicious scripts that may compromise sensitive information.