CVE-2016-4016
MEDIUMSAP MII 15 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in SAP Manufacturing Integration and Intelligence (aka MII, formerly xMII) 15 allows remote attackers to inject arbitrary web script or HTML via the title parameter to webdynpro/resources/sap.com/xapps~xmii~ui~admin~navigation/NavigationApplication, aka SAP Security Note 2201295.
References (4)
Scores
CVSS v3
6.1
EPSS
0.0049
EPSS Percentile
65.4%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Classification
CWE
CWE-79
Status
draft
Affected Products (1)
sap/java_as
Timeline
Published
Apr 14, 2016
Tracked Since
Feb 18, 2026