Cross-site scripting (XSS) vulnerability in the help component of SAP BusinessObjects Financial Consolidation 10.0.0.1933 allows remote attackers to inject arbitrary web script or HTML via a GET request. /finance/help/en/frameset.htm is the URI for this component. The vendor response is SAP Security Note 2368106.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2017-03-16T03:49:00
Updated: 2024-08-05T15:18:49.741Z
Reserved: 2017-02-17T00:00:00
Link: CVE-2017-6061
Vulnrichment
No data.
NVD
Status : Modified
Published: 2017-03-16T04:59:00.200
Modified: 2024-11-21T03:29:00.967
Link: CVE-2017-6061
Redhat
No data.