Description
Due to insufficient input validation, SAP CRM
WebClient UI allows an unauthenticated attacker to craft a URL link which
embeds a malicious script. When a victim clicks on this link, the script will
be executed in the victim's browser giving the attacker the ability to access
and/or modify information with no effect on availability of the application.
Published: 2024-06-11
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-34985 Due to insufficient input validation, SAP CRM WebClient UI allows an unauthenticated attacker to craft a URL link which embeds a malicious script. When a victim clicks on this link, the script will be executed in the victim's browser giving the attacker the ability to access and/or modify information with no effect on availability of the application.
History

Fri, 16 Aug 2024 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Sap
Sap customer Relationship Management Webclient Ui
CPEs cpe:2.3:a:sap:customer_relationship_management_webclient_ui:103:*:*:*:*:*:*:*
cpe:2.3:a:sap:customer_relationship_management_webclient_ui:104:*:*:*:*:*:*:*
cpe:2.3:a:sap:customer_relationship_management_webclient_ui:105:*:*:*:*:*:*:*
cpe:2.3:a:sap:customer_relationship_management_webclient_ui:106:*:*:*:*:*:*:*
cpe:2.3:a:sap:customer_relationship_management_webclient_ui:107:*:*:*:*:*:*:*
cpe:2.3:a:sap:customer_relationship_management_webclient_ui:701:*:*:*:*:*:*:*
cpe:2.3:a:sap:customer_relationship_management_webclient_ui:730:*:*:*:*:*:*:*
cpe:2.3:a:sap:customer_relationship_management_webclient_ui:731:*:*:*:*:*:*:*
cpe:2.3:a:sap:customer_relationship_management_webclient_ui:746:*:*:*:*:*:*:*
cpe:2.3:a:sap:customer_relationship_management_webclient_ui:747:*:*:*:*:*:*:*
cpe:2.3:a:sap:customer_relationship_management_webclient_ui:748:*:*:*:*:*:*:*
cpe:2.3:a:sap:customer_relationship_management_webclient_ui:800:*:*:*:*:*:*:*
cpe:2.3:a:sap:customer_relationship_management_webclient_ui:801:*:*:*:*:*:*:*
cpe:2.3:a:sap:customer_relationship_management_webclient_ui:s4fnd_102:*:*:*:*:*:*:*
cpe:2.3:a:sap:customer_relationship_management_webclient_ui:webcuif_700:*:*:*:*:*:*:*
Vendors & Products Sap
Sap customer Relationship Management Webclient Ui

Subscriptions

Sap Customer Relationship Management Webclient Ui
cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2024-08-02T02:59:22.207Z

Reserved: 2024-05-07T05:46:11.657Z

Link: CVE-2024-34686

cve-icon Vulnrichment

Updated: 2024-08-02T02:59:22.207Z

cve-icon NVD

Status : Modified

Published: 2024-06-11T03:15:11.080

Modified: 2024-11-21T09:19:11.657

Link: CVE-2024-34686

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses