CVE-2010-2904
Summary
| CVE | CVE-2010-2904 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-07-28 21:30:02 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Multiple cross-site scripting (XSS) vulnerabilities in the System Landscape Directory (SLD) component 6.4 through 7.02 in SAP NetWeaver allow remote attackers to inject arbitrary web script or HTML via the (1) action parameter to testsdic and the (2) helpstring parameter to paramhelp.jsp. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Sap | Netweaver | All | All | All | All |
| Application | Sap | Netweaver | 6.4 | All | All | All |
| Application | Sap | Netweaver | 7.0 | All | All | All |
| Application | Sap | System Landscape Directory | 6.4 | All | All | All |
| Application | Sap | System Landscape Directory | 7.0 | All | All | All |
| Application | Sap | System Landscape Directory | 7.02 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.osvdb.org/66639 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| service.sap.com/sap/support/notes/1416047 | af854a3a-2127-422b-91ae-364da2661108 | service.sap.com | |
| www.osvdb.org/66640 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| Digital Security Research Group - [DSECRG-09-068] SAP NetWaver SLD - Multiple XSS | af854a3a-2127-422b-91ae-364da2661108 | dsecrg.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Files ≈ Packet Storm | af854a3a-2127-422b-91ae-364da2661108 | packetstormsecurity.org | |
| SAP NetWeaver System Landscape Directory Component Cross-Site Scripting - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.