CVE-2011-4707
Status: ModifiedMedium (4.3)—
Multiple cross-site scripting (XSS) vulnerabilities in the Virus Scan Interface in SAP Netweaver allow remote attackers to inject arbitrary web script or HTML via the (1) instname parameter to the VsiTestScan servlet and (2) name parameter to the VsiTestServlet servlet.
CVSS
- Version: 2.0
- Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N
- Base score: 4.3
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 1.09%
- Percentile among all scored CVEs: 64
- Score date: 10/8/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-79
References
- http://dsecrg.com/pages/vul/show.php?id=336
- http://www.sdn.sap.com/irj/sdn/index?rid=/webcontent/uuid/c05604f6-4eb3-2d10-eea7-ceb666083a6a
- http://www.securityfocus.com/archive/1/520554/100/0/threaded
- https://erpscan.io/advisories/dsecrg-11-036-sap-netwaver-virus-scan-interface-multiple-xss/
- https://service.sap.com/sap/support/notes/1546307
- http://dsecrg.com/pages/vul/show.php?id=336
- http://www.sdn.sap.com/irj/sdn/index?rid=/webcontent/uuid/c05604f6-4eb3-2d10-eea7-ceb666083a6a
- http://www.securityfocus.com/archive/1/520554/100/0/threaded
- https://erpscan.io/advisories/dsecrg-11-036-sap-netwaver-virus-scan-interface-multiple-xss/
- https://service.sap.com/sap/support/notes/1546307
Raw JSON (NVD)
Show
{
"id": "CVE-2011-4707",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2011-12-08T19:55:03.720",
"references": [
{
"url": "http://dsecrg.com/pages/vul/show.php?id=336",
"source": "cve@mitre.org"
},
{
"url": "http://www.sdn.sap.com/irj/sdn/index?rid=/webcontent/uuid/c05604f6-4eb3-2d10-eea7-ceb666083a6a",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/520554/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "https://erpscan.io/advisories/dsecrg-11-036-sap-netwaver-virus-scan-interface-multiple-xss/",
"source": "cve@mitre.org"
},
{
"url": "https://service.sap.com/sap/support/notes/1546307",
"source": "cve@mitre.org"
},
{
"url": "http://dsecrg.com/pages/vul/show.php?id=336",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.sdn.sap.com/irj/sdn/index?rid=/webcontent/uuid/c05604f6-4eb3-2d10-eea7-ceb666083a6a",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/520554/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://erpscan.io/advisories/dsecrg-11-036-sap-netwaver-virus-scan-interface-multiple-xss/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://service.sap.com/sap/support/notes/1546307",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Multiple cross-site scripting (XSS) vulnerabilities in the Virus Scan Interface in SAP Netweaver allow remote attackers to inject arbitrary web script or HTML via the (1) instname parameter to the VsiTestScan servlet and (2) name parameter to the VsiTestServlet servlet."
},
{
"lang": "es",
"value": "Múltiples vulnerabilidades de ejecución de secuencias de comandos en sitios cruzados en el Virus Scan Interface en SAP Netweaver, permite a usuarios remotos inyectar secuencias de comandos web o HTML a través de los parámetros (1) instname en el servlet VsiTestScan y (2) name en el servlet VsiTestServlet."
}
],
"lastModified": "2026-06-16T23:35:16.670",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:sap:netweaver:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5007E3B7-3C36-4256-9E01-51C6F52FD0FF"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}