5.4
CVE-2024-21738
- EPSS 0.2%
- Published 09.01.2024 02:15:46
- Last modified 21.11.2024 08:54:54
- Source cna@sap.com
- Teams watchlist Login
- Open Login
SAP NetWeaver ABAP Application Server and ABAP Platform do not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. An attacker with low privileges can cause limited impact to confidentiality of the application data after successful exploitation.
Data is provided by the National Vulnerability Database (NVD)
SAP ≫ Netweaver Application Server Abap Version79 SwEditionsap_basis
SAP ≫ Netweaver Application Server Abap Version700 SwEditionsap_basis
SAP ≫ Netweaver Application Server Abap Version701 SwEditionsap_basis
SAP ≫ Netweaver Application Server Abap Version702 SwEditionsap_basis
SAP ≫ Netweaver Application Server Abap Version731 SwEditionsap_basis
SAP ≫ Netweaver Application Server Abap Version740 SwEditionsap_basis
SAP ≫ Netweaver Application Server Abap Version750 SwEditionsap_basis
SAP ≫ Netweaver Application Server Abap Version751 SwEditionsap_basis
SAP ≫ Netweaver Application Server Abap Version752 SwEditionsap_basis
SAP ≫ Netweaver Application Server Abap Version753 SwEditionsap_basis
SAP ≫ Netweaver Application Server Abap Version754 SwEditionsap_basis
SAP ≫ Netweaver Application Server Abap Version755 SwEditionsap_basis
SAP ≫ Netweaver Application Server Abap Version756 SwEditionsap_basis
SAP ≫ Netweaver Application Server Abap Version757 SwEditionsap_basis
SAP ≫ Netweaver Application Server Abap Version758 SwEditionsap_basis
SAP ≫ Netweaver Application Server Abap Version793 SwEditionsap_basis
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.2% | 0.421 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 5.4 | 2.3 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
|
cna@sap.com | 4.1 | 2.3 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.