CVE-2018-11415: SAP Internet Transaction Server

Medium severity, CVSS 6.1. EPSS: 8.1% chance of exploitation in the next 30 days.

SAP Internet Transaction Server (ITS) 6200.X.X has Reflected Cross Site Scripting (XSS) via certain wgate URIs. NOTE: the vendor has reportedly indicated that there will not be any further releases of this product.

Affected products

  • SAP Internet Transaction Server: version 6.20 only

Published 2018-05-24. Last modified 2026-06-17.