Description
Applications based on SAP GUI for HTML in SAP NetWeaver AS ABAP - versions 7.89, 7.93, do not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. A successful attack can allow a malicious attacker to access and modify data through their ability to execute code in a user’s browser. There is no impact on the availability of the system
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-25094 | Applications based on SAP GUI for HTML in SAP NetWeaver AS ABAP - versions 7.89, 7.93, do not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. A successful attack can allow a malicious attacker to access and modify data through their ability to execute code in a user’s browser. There is no impact on the availability of the system |
References
History
Wed, 26 Feb 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sap
Sap netweaver As Abap |
|
| CPEs | cpe:2.3:a:sap:netweaver_as_abap:sap_ui_7.89:*:*:*:*:*:*:* cpe:2.3:a:sap:netweaver_as_abap:sap_ui_7.93:*:*:*:*:*:*:* |
|
| Vendors & Products |
Sap
Sap netweaver As Abap |
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2024-08-02T00:41:55.900Z
Reserved: 2024-02-27T06:26:16.787Z
Link: CVE-2024-27902
Updated: 2024-05-23T19:01:17.161Z
Status : Analyzed
Published: 2024-03-12T01:15:50.193
Modified: 2025-02-26T15:15:08.143
Link: CVE-2024-27902
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD