CVE-2010-2904
SAP NetWeaver <7.02 - XSS
Title source: llmDescription
Multiple cross-site scripting (XSS) vulnerabilities in the System Landscape Directory (SLD) component 6.4 through 7.02 in SAP NetWeaver allow remote attackers to inject arbitrary web script or HTML via the (1) action parameter to testsdic and the (2) helpstring parameter to paramhelp.jsp.
References (8)
Scores
EPSS
0.0054
EPSS Percentile
67.5%
Classification
CWE
CWE-79
Status
published
Affected Products (7)
sap/system_landscape_directory
sap/system_landscape_directory
sap/system_landscape_directory
sap/netweaver
sap/netweaver
sap/netweaver
n/a/n/a
Timeline
Published
Jul 28, 2010
Tracked Since
Feb 18, 2026