VYPR

Netweaver Business Client

by SAP

CVEs (2)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2010-45560.010.10Dec 17, 2010Stack-based buffer overflow in the SapThemeRepository ActiveX control (sapwdpcd.dll) in SAP NetWeaver Business Client allows remote attackers to execute arbitrary code via the (1) Load and (2) LoadTheme methods.
CVE-2014-41600.000.00Jun 13, 2014Multiple cross-site scripting (XSS) vulnerabilities in the testcanvas node in SAP NetWeaver Business Client (NWBC) allow remote attackers to inject arbitrary web script or HTML via the (1) title or (2) sap-accessibility parameter.