CVE-2008-2421
SAP Application Server vulnerability analysis and mitigation

Cross-site scripting (XSS) vulnerability in the Web GUI in SAP Web Application Server (WAS) 7.0, Web Dynpro for ABAP (aka WD4A or WDA), and Web Dynpro for BSP allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI under bc/gui/sap/its/webgui/.


SourceNVD

Related SAP Application Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2020-6262HIGH8.8
  • SAP Application Server logoSAP Application Server
  • cpe:2.3:a:sap:application_server
NoNoMay 12, 2020
CVE-2007-3615HIGH7.8
  • SAP Application Server logoSAP Application Server
  • cpe:2.3:a:sap:sap_web_application_server
NoNoJul 06, 2007
CVE-2009-4603MEDIUM5
  • SAP Application Server logoSAP Application Server
  • cpe:2.3:a:sap:sap_kernel
NoYesJan 12, 2010
CVE-2015-7968MEDIUM4.3
  • SAP Application Server logoSAP Application Server
  • cpe:2.3:a:sap:netweaver_application_server
NoYesMar 09, 2020
CVE-2008-2421MEDIUM4.3
  • SAP Application Server logoSAP Application Server
  • cpe:2.3:a:sap:sap_web_application_server
NoNoMay 23, 2008

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management