Vulnerability Description
Cross-site scripting (XSS) vulnerability in SAP Web Dynpro Java (BC-WD-JAV) in SAP NetWeaver Nw04 SP15 through SP19 and Nw04s SP7 through SP11, aka SAP Java Technology Services 640 before SP20 and SAP Web Dynpro Runtime Core Components 700 before SP12, allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Netweaver Nw04 | sp15 |
| Sap | Netweaver Nw04S | sp7 |
| Sap | Sap Basis Component 640 | <= sp19 |
| Sap | Sap Basis Component 700 | <= sp11 |
References
- http://osvdb.org/37748
- http://secunia.com/advisories/25866
- http://securityreason.com/securityalert/2850
- http://www.csnc.ch/advisory/sap01.html
- http://www.securityfocus.com/archive/1/472341/100/0/threaded
- http://www.vupen.com/english/advisories/2007/2381
- http://osvdb.org/37748
- http://secunia.com/advisories/25866
- http://securityreason.com/securityalert/2850
- http://www.csnc.ch/advisory/sap01.html
- http://www.securityfocus.com/archive/1/472341/100/0/threaded
- http://www.vupen.com/english/advisories/2007/2381
FAQ
What is CVE-2007-3496?
CVE-2007-3496 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Cross-site scripting (XSS) vulnerability in SAP Web Dynpro Java (BC-WD-JAV) in SAP NetWeaver Nw04 SP15 through SP19 and Nw04s SP7 through SP11, aka SAP Java Technology Services 640 before SP20 and SAP...
How severe is CVE-2007-3496?
CVE-2007-3496 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-3496?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Netweaver Nw04, Sap Netweaver Nw04S, Sap Sap Basis Component 640, Sap Sap Basis Component 700.