Description
SAP Companion - version <3.1.38, has a URL with parameter that could be vulnerable to XSS attack. The attacker could send a malicious link to a user that would possibly allow an attacker to retrieve the sensitive information and cause minor impact on the integrity of the web application.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-19725 | SAP Companion - version <3.1.38, has a URL with parameter that could be vulnerable to XSS attack. The attacker could send a malicious link to a user that would possibly allow an attacker to retrieve the sensitive information and cause minor impact on the integrity of the web application. |
References
History
Wed, 16 Oct 2024 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sap
Sap companion |
|
| CPEs | cpe:2.3:a:sap:companion:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Sap
Sap companion |
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2024-08-01T22:35:34.889Z
Reserved: 2024-01-05T10:21:35.256Z
Link: CVE-2024-22129
Updated: 2024-08-01T22:35:34.889Z
Status : Modified
Published: 2024-02-13T04:15:08.133
Modified: 2024-11-21T08:55:38.467
Link: CVE-2024-22129
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD