漏洞标题
SAP NetWeaver Application Server ABAP (基于SAP GUI for HTML的应用)中的跨站脚本(XSS)漏洞
漏洞描述信息
SAP NetWeaver Application Server ABAP 未充分编码用户可控输入,导致基于DOM的跨站脚本攻击(XSS)漏洞。这使得无权限的攻击者能够构造恶意web消息,利用WEBGUI功能。在成功利用此漏洞后,恶意的JavaScript载荷会在受害者浏览器的作用域内执行,可能危及他们的数据或操纵浏览器内容。这将对机密性和完整性造成有限影响,对可用性没有影响。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
漏洞类别
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
漏洞标题
Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP (applications based on SAP GUI for HTML)
漏洞描述信息
SAP NetWeaver Application Server ABAP does not sufficiently encode user-controlled inputs, leading to DOM-basedCross-Site Scripting (XSS) vulnerability. This allows an attacker with no privileges, to craft a malicious web message that exploits WEBGUI functionality. On successful exploitation, the malicious JavaScript payload executes in the scope of victim�s browser potentially compromising their data and/or manipulating browser content. This leads to a limited impact on confidentiality and integrity. There is no impact on availability
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
漏洞类别
在Web页面生成时对输入的转义处理不恰当(跨站脚本)