Vulnerability Description
Cross-Site scripting (XSS) in SAP Business Warehouse Universal Data Integration, from 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, due to insufficient encoding of user controlled inputs.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Business Warehouse Universal Data Integration | 7.10 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/102148Third Party AdvisoryVDB Entry
- https://blogs.sap.com/2017/12/12/sap-security-patch-day-december-2017/Vendor Advisory
- https://launchpad.support.sap.com/#/notes/2537545Permissions Required
- http://www.securityfocus.com/bid/102148Third Party AdvisoryVDB Entry
- https://blogs.sap.com/2017/12/12/sap-security-patch-day-december-2017/Vendor Advisory
- https://launchpad.support.sap.com/#/notes/2537545Permissions Required
FAQ
What is CVE-2017-16685?
CVE-2017-16685 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Cross-Site scripting (XSS) in SAP Business Warehouse Universal Data Integration, from 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, due to insufficient encoding of user controlled inputs.
How severe is CVE-2017-16685?
CVE-2017-16685 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-16685?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Business Warehouse Universal Data Integration.