Home
MEDIUM: 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NDefault status
unaffected
DW4CORE 100
affected
200
affected
300
affected
400
affected
916
affected
SAP_BW 730
affected
731
affected
740
affected
750
affected
751
affected
752
affected
753
affected
754
affected
756
affected
757
affected
758
affected
Description
SAP Business Warehouse (Business Explorer Web) allows an attacker to create a malicious link. If an authenticated user clicks on this link, the injected script gets executed within the scope of victim�s browser. This potentially leads to an impact on confidentiality and integrity. Availability is not impacted.
Problem types
CWE-79: Improper Neutralization of Input During Web Page Generation
Product status
DW4CORE 100
200
300
400
916
SAP_BW 730
731
740
750
751
752
753
754
756
757
758