VulnerabilityModified
CVE-2018-2504
SAP NetWeaver AS Java Web Container service does not validate against whitelist the HTTP host header which can result in HTTP Host Header Manipulation or Cross-Site Scripting (XSS) vulnerability.
MEDIUM 6.1EPSS 1.06%
Does this matter?
Lower severity and a low EPSS score (1.06%). Track it; it rarely justifies an emergency change on its own.
Description
SAP NetWeaver AS Java Web Container service does not validate against whitelist the HTTP host header which can result in HTTP Host Header Manipulation or Cross-Site Scripting (XSS) vulnerability. This is fixed in versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 1.06% probability · 63th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- sap/netweaver application server java
- Source
- cna@sap.com
References
- http://www.securityfocus.com/bid/106150Third Party Advisory, VDB Entry
- https://launchpad.support.sap.com/#/notes/2718993Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=508559699Vendor Advisory
- http://www.securityfocus.com/bid/106150Third Party Advisory, VDB Entry
- https://launchpad.support.sap.com/#/notes/2718993Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=508559699Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.