VendorsSAPj2ee_engineall versions
Vulnerabilities

SAP j2ee Engine

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2018-17861
A cross-site scripting (XSS) vulnerability in SAP J2EE Engine/7.01/Portal/EPP allows remote attackers to inject arbitrary web script via the wsdlLib parameter to /ctcprotocol/Protocol. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
Published 2021-08-09 · Modified
6.1EPSS 0.015
CVE-2018-17862
A cross-site scripting (XSS) vulnerability in SAP J2EE Engine/7.01/Fiori allows remote attackers to inject arbitrary web script via the sys_jdbc parameter to /TestJDBC_Web/test2. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
Published 2021-08-09 · Modified
6.1EPSS 0.014
CVE-2018-17865
A cross-site scripting (XSS) vulnerability in SAP J2EE Engine 7.01 allows remote attackers to inject arbitrary web script via the wsdlPath parameter to /ctcprotocol/Protocol. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
Published 2021-08-09 · Modified
6.1EPSS 0.007
CVE-2013-7357
Unspecified vulnerability in the configuration service in SAP J2EE Engine allows remote attackers to obtain credential information via unknown vectors.
Published 2014-04-10 · Modified
5.0EPSS 0.012