6.1
CVE-2023-27499
- EPSS 0.42%
- Veröffentlicht 11.04.2023 03:15:07
- Zuletzt bearbeitet 21.11.2024 07:53:01
- Quelle cna@sap.com
- Teams Watchlist Login
- Unerledigt Login
SAP GUI for HTML - versions KERNEL 7.22, 7.53, 7.54, 7.77, 7.81, 7.85, 7.89, 7.91, KRNL64UC, 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT does not sufficiently encode user-controlled inputs, resulting in a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could craft a malicious URL and lure the victim to click, the script supplied by the attacker will execute in the victim user's browser. The information from the victim's web browser can either be modified or read and sent to the attacker.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SAP ≫ Netweaver Application Server Abap Version7.22
SAP ≫ Netweaver Application Server Abap Version7.53
SAP ≫ Netweaver Application Server Abap Version7.54
SAP ≫ Netweaver Application Server Abap Version7.77
SAP ≫ Netweaver Application Server Abap Version7.81
SAP ≫ Netweaver Application Server Abap Version7.85
SAP ≫ Netweaver Application Server Abap Version7.89
SAP ≫ Netweaver Application Server Abap Version7.91
SAP ≫ Netweaver Application Server Abap Versionkrnl64uc
SAP ≫ Netweaver Application Server Abap Versionkrnl64uc_7.22
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.42% | 0.605 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 6.1 | 2.8 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
|
cna@sap.com | 6.1 | 2.8 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.