CVE-2010-2904

SAP NetWeaver <7.02 - XSS

Title source: llm

Description

Multiple cross-site scripting (XSS) vulnerabilities in the System Landscape Directory (SLD) component 6.4 through 7.02 in SAP NetWeaver allow remote attackers to inject arbitrary web script or HTML via the (1) action parameter to testsdic and the (2) helpstring parameter to paramhelp.jsp.

Scores

EPSS 0.0054
EPSS Percentile 67.5%

Classification

CWE
CWE-79
Status published

Affected Products (7)

sap/system_landscape_directory
sap/system_landscape_directory
sap/system_landscape_directory
sap/netweaver
sap/netweaver
sap/netweaver
n/a/n/a

Timeline

Published Jul 28, 2010
Tracked Since Feb 18, 2026