Description
Due to weak encoding of user-controlled input in
SAP NetWeaver Knowledge Management XMLEditor which allows malicious scripts can
be executed in the application, potentially leading to a Cross-Site Scripting
(XSS) vulnerability. This has no impact on the availability of the application
but it has a low impact on its confidentiality and integrity.
Published: 2024-07-09
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-34984 Due to weak encoding of user-controlled input in SAP NetWeaver Knowledge Management XMLEditor which allows malicious scripts can be executed in the application, potentially leading to a Cross-Site Scripting (XSS) vulnerability. This has no impact on the availability of the application but it has a low impact on its confidentiality and integrity.
History

Thu, 29 Aug 2024 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Sap
Sap netweaver Knowledge Management And Collaboration \(kmc-cm\)
CPEs cpe:2.3:a:sap:netweaver_knowledge_management_and_collaboration_\(kmc-cm\):7.50:*:*:*:*:*:*:*
Vendors & Products Sap
Sap netweaver Knowledge Management And Collaboration \(kmc-cm\)

Subscriptions

Sap Netweaver Knowledge Management And Collaboration \(kmc-cm\)
cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2024-08-02T02:59:21.683Z

Reserved: 2024-05-07T05:46:11.657Z

Link: CVE-2024-34685

cve-icon Vulnrichment

Updated: 2024-08-02T02:59:21.683Z

cve-icon NVD

Status : Modified

Published: 2024-07-09T04:15:12.090

Modified: 2024-11-21T09:19:11.507

Link: CVE-2024-34685

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses