📦

sap_web_application_server

Vendor: sap

Actively Exploited 0 CISA KEV List
PoC / Exploits 6 Code Available
Total RCEs 1 Remote Access
Total CVEs 28 Total Indexed
Avg. EPSS 4.84% Exploit Prob.
Latest CVE CVE-2009-4603 Jan 12

Security Vulnerability Index

Page 2 / 3
4.3 CVSS
CVE-2005-3635
Exploit Found

Multiple cross-site scripting (XSS) vulnerabilities in SAP Web Application Server (WAS) 6.10 through 7.00 allow remote attackers to inject arbitrary web script or HTML via (1) the sap-syscmd in sap-syscmd and (2) the BspApplication field in the SYSTEM PUBLIC test application.

EPSS: 5.03%
5.0 CVSS
CVE-2005-3634
Exploit Found

frameset.htm in the BSP runtime in SAP Web Application Server (WAS) 6.10 through 7.00 allows remote attackers to log users out and redirect them to arbitrary web sites via a close command in the sap-sessioncmd parameter and a URL in the sap-exiturl parameter.

EPSS: 17.76%