Total vulnerabilities in the database
SAP NetWeaver AS Java Web Container service does not validate against whitelist the HTTP host header which can result in HTTP Host Header Manipulation or Cross-Site Scripting (XSS) vulnerability. This is fixed in versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50.
Software | From | Fixed in |
---|---|---|
sap / netweaver_application_server_java | 7.20 | 7.20.x |
sap / netweaver_application_server_java | 7.30 | 7.30.x |
sap / netweaver_application_server_java | 7.31 | 7.31.x |
sap / netweaver_application_server_java | 7.40 | 7.40.x |
sap / netweaver_application_server_java | 7.50 | 7.50.x |
sap / netweaver_application_server_java | 7.10 | 7.10.x |
sap / netweaver_application_server_java | 7.11 | 7.11.x |