Medium severity6.1NVD Advisory· Published Jul 25, 2017· Updated May 13, 2026
CVE-2017-11460
CVE-2017-11460
Description
Cross-site scripting (XSS) vulnerability in the DataArchivingService servlet in SAP NetWeaver Portal 7.4 allows remote attackers to inject arbitrary web script or HTML via the responsecode parameter to shp/shp_result.jsp, aka SAP Security Note 2308535.
Affected products
2cpe:2.3:a:sap:netweaver_portal:7.4:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:sap:netweaver_portal:7.4:*:*:*:*:*:*:*
- (no CPE)range: =7.4
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3News mentions
0No linked articles in our index yet.