Description
Cross-site scripting (XSS) vulnerability in uddiclient/process in the UDDI client in SAP NetWeaver Application Server (Java) 7.0 allows remote attackers to inject arbitrary web script or HTML via the TModel Key field.
Affected products
- SAP / netweaver7.0 – 7.0
References
- MISChttp://osvdb.org/57000
- MISChttp://www.dsecrg.com/pages/vul/show.php?id=133
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/52429
- MISChttp://www.securityfocus.com/archive/1/505697/100/0/threaded
- MISChttp://www.securitytracker.com/id?1022731
- MISChttps://service.sap.com/sap/support/notes/1322098
- MISChttp://www.securityfocus.com/bid/36034
- VENDOR_ADVISORYhttp://secunia.com/advisories/36228