CVE-2015-2072
Multiple cross-site scripting (XSS) vulnerabilities in SAP HANA 73 (1.00.73.00.389160) and HANA Developer Edition 80 (1.00.80.00.391861) allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to (1) ide/core/plugins/editor/templates/trace/hanaTraceDetailService.xsjs or (2) xs/ide/editor/templates/trace/hanaTraceDetailService.xsjs, aka SAP Note 2069676.
- Affected products
- Sap Hana, Sap Hana Developer Edition
- Sap Hana
- = 1.00.73.00.389160, 1.00.80.00.391861
- Fix
- Available
- CVSS 2.0
- 4.3 MEDIUM
- EPSS
- 1.9% (78th percentile)
- Weakness
- CWE-79
- NVD status
- Modified
- Published
- 2015-02-27
CVE-2015-2072 at NVD
No indexed exploits for CVE-2015-2072 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2015-2072 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.