CVE-2008-1846

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
16/04/2008
Last modified:
09/04/2025

Description

The default configuration of SAP NetWeaver before 7.0 SP15 does not enable the "Always Use Secure HTML Editor" (aka Editor Security or Secure Editing) parameter, which allows remote attackers to conduct cross-site scripting (XSS) attacks by entering feedback for a file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sap:netweaver:*:sp8:*:*:*:*:*:* 7.0 (including)