CVE-2018-2371
N/A
N/A
Summary
The SAML 2.0 service provider of SAP Netweaver AS Java Web Application, 7.50, does not sufficiently encode user controlled inputs, which results in Cross-Site Scripting (XSS) vulnerability.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| SAP SE | SAP NetWeaver Java Web Application | 7.50 | affected |
Weaknesses
- Cross-Site Scripting (XSS)
ADP Enrichment
CVE Program Container
Additional References
- http://www.securityfocus.com/bid/103005
- https://launchpad.support.sap.com/#/notes/2560741
- https://blogs.sap.com/2018/02/13/sap-security-patch-day-february-2018/
References
- http://www.securityfocus.com/bid/103005
- https://launchpad.support.sap.com/#/notes/2560741
- https://blogs.sap.com/2018/02/13/sap-security-patch-day-february-2018/
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.