Total vulnerabilities in the database
An attacker with no prior authentication could craft and send malicious script to SAP GUI for HTML within Fiori Launchpad, resulting in reflected cross-site scripting attack. This could lead to stealing session information and impersonating the affected user.
Software | From | Fixed in |
---|---|---|
sap / netweaver_application_server_abap | kernel_7.77 | kernel_7.77.x |
sap / netweaver_application_server_abap | 7.81 | 7.81.x |
sap / netweaver_application_server_abap | 7.85 | 7.85.x |
sap / netweaver_application_server_abap | 7.89 | 7.89.x |
sap / netweaver_application_server_abap | 7.54 | 7.54.x |