Description
Due to insufficient input validation, SAP CRM
WebClient UI allows an unauthenticated attacker to craft a URL link which
embeds a malicious script. When a victim clicks on this link, the script will
be executed in the victim's browser giving the attacker the ability to access
and/or modify information with no effect on availability of the application.
WebClient UI allows an unauthenticated attacker to craft a URL link which
embeds a malicious script. When a victim clicks on this link, the script will
be executed in the victim's browser giving the attacker the ability to access
and/or modify information with no effect on availability of the application.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-34985 | Due to insufficient input validation, SAP CRM WebClient UI allows an unauthenticated attacker to craft a URL link which embeds a malicious script. When a victim clicks on this link, the script will be executed in the victim's browser giving the attacker the ability to access and/or modify information with no effect on availability of the application. |
References
History
Fri, 16 Aug 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sap
Sap customer Relationship Management Webclient Ui |
|
| CPEs | cpe:2.3:a:sap:customer_relationship_management_webclient_ui:103:*:*:*:*:*:*:* cpe:2.3:a:sap:customer_relationship_management_webclient_ui:104:*:*:*:*:*:*:* cpe:2.3:a:sap:customer_relationship_management_webclient_ui:105:*:*:*:*:*:*:* cpe:2.3:a:sap:customer_relationship_management_webclient_ui:106:*:*:*:*:*:*:* cpe:2.3:a:sap:customer_relationship_management_webclient_ui:107:*:*:*:*:*:*:* cpe:2.3:a:sap:customer_relationship_management_webclient_ui:701:*:*:*:*:*:*:* cpe:2.3:a:sap:customer_relationship_management_webclient_ui:730:*:*:*:*:*:*:* cpe:2.3:a:sap:customer_relationship_management_webclient_ui:731:*:*:*:*:*:*:* cpe:2.3:a:sap:customer_relationship_management_webclient_ui:746:*:*:*:*:*:*:* cpe:2.3:a:sap:customer_relationship_management_webclient_ui:747:*:*:*:*:*:*:* cpe:2.3:a:sap:customer_relationship_management_webclient_ui:748:*:*:*:*:*:*:* cpe:2.3:a:sap:customer_relationship_management_webclient_ui:800:*:*:*:*:*:*:* cpe:2.3:a:sap:customer_relationship_management_webclient_ui:801:*:*:*:*:*:*:* cpe:2.3:a:sap:customer_relationship_management_webclient_ui:s4fnd_102:*:*:*:*:*:*:* cpe:2.3:a:sap:customer_relationship_management_webclient_ui:webcuif_700:*:*:*:*:*:*:* |
|
| Vendors & Products |
Sap
Sap customer Relationship Management Webclient Ui |
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2024-08-02T02:59:22.207Z
Reserved: 2024-05-07T05:46:11.657Z
Link: CVE-2024-34686
Updated: 2024-08-02T02:59:22.207Z
Status : Modified
Published: 2024-06-11T03:15:11.080
Modified: 2024-11-21T09:19:11.657
Link: CVE-2024-34686
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD