SAP NetWeaver Application Server for ABAP and ABAP Platform do not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. An attacker can control code that is executed within a user’s browser, which could result in modification, deletion of data, including accessing or deleting files, or stealing session cookies which an attacker could use to hijack a user’s session. Hence, this could have impact on Confidentiality, Integrity and Availability of the system.
| Software | From | Fixed in |
|---|---|---|
| sap / sap_basis | 700 | 700.x |
| sap / sap_basis | 701 | 701.x |
| sap / sap_basis | 702 | 702.x |
| sap / sap_basis | 731 | 731.x |
| sap / sap_basis | 740 | 740.x |
| sap / sap_basis | 750 | 750.x |
| sap / sap_basis | 751 | 751.x |
| sap / sap_basis | 752 | 752.x |
| sap / sap_basis | 753 | 753.x |
| sap / sap_basis | 754 | 754.x |
| sap / sap_basis | 755 | 755.x |
| sap / sap_basis | 756 | 756.x |
| sap / sap_basis | 757 | 757.x |
| sap / sap_basis | 758 | 758.x |
| sap / sap_basis | 795 | 795.x |
| sap / sap_basis | 796 | 796.x |