Sap hana Extended Application Services Cross-Site Scripting Vulnerability
Release date:
Updated on: 2014-08-02
Affected Systems:
Sap hana Extended Application Services
Description:
--------------------------------------------------------------------------------
Bugtraq id: 68952
CVE (CAN) ID: CVE-2014-5172
Sap hana Extended Application Services (XS) is the development environment for Web applications in the Application server, Web server, and sap hana System.
Sap hana Extend Application Services (XS) has a cross-site scripting vulnerability in XS Administration Tools, which allows remote attackers to exploit this vulnerability to inject arbitrary Web scripts or HTML.
<* Source: Sergio Abraham
Link: http://seclists.org/fulldisclosure/2014/Jul/153
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
SAP
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://service.sap.com/sap/support/notes/1993349
This article permanently updates the link address: