CVE-2007-3496
Summary
| CVE | CVE-2007-3496 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-06-29 18:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Cross-site scripting (XSS) vulnerability in SAP Web Dynpro Java (BC-WD-JAV) in SAP NetWeaver Nw04 SP15 through SP19 and Nw04s SP7 through SP11, aka SAP Java Technology Services 640 before SP20 and SAP Web Dynpro Runtime Core Components 700 before SP12, allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header. |
Risk And Classification
Primary CVSS: v2.0 4.3 from [email protected]
AV:N/AC:M/Au:N/C:N/I:P/A:N
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Sap | Netweaver Nw04 | sp15 | All | All | All |
| Application | Sap | Netweaver Nw04 | sp16 | All | All | All |
| Application | Sap | Netweaver Nw04 | sp17 | All | All | All |
| Application | Sap | Netweaver Nw04 | sp18 | All | All | All |
| Application | Sap | Netweaver Nw04 | sp19 | All | All | All |
| Application | Sap | Netweaver Nw04s | sp10 | All | All | All |
| Application | Sap | Netweaver Nw04s | sp11 | All | All | All |
| Application | Sap | Netweaver Nw04s | sp7 | All | All | All |
| Application | Sap | Netweaver Nw04s | sp8 | All | All | All |
| Application | Sap | Netweaver Nw04s | sp9 | All | All | All |
| Application | Sap | Sap Basis Component 640 | All | All | All | All |
| Application | Sap | Sap Basis Component 700 | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SAP Products Cross-Site Scripting Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Compass Secure Server | af854a3a-2127-422b-91ae-364da2661108 | www.csnc.ch | |
| osvdb.org/37748 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| SecurityReason - SAP Web Dynpro Java (BC-WD-JAV) Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.