5.4
CVE-2024-39595
- EPSS 0.24%
- Veröffentlicht 09.07.2024 05:15:12
- Zuletzt bearbeitet 28.10.2025 18:41:39
- Erkennungen
[CVE-2024-39594] Multiple Cross-Site Scripting (XSS) vulnerabilities in SAP Business Warehouse - Business Planning and Simulation
SAP Business Warehouse - Business Planning and Simulation application does not sufficiently encode user-controlled inputs, resulting in Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability allows users to modify website content and on successful exploitation, an attacker can cause low impact to the confidentiality and integrity of the application.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SAP ≫ Business Warehouse Version 700
SAP ≫ Business Warehouse Version 701
SAP ≫ Business Warehouse Version 702
SAP ≫ Business Warehouse Version 730
SAP ≫ Business Warehouse Version 731
SAP ≫ Business Warehouse Version 740
SAP ≫ Business Warehouse Version 750
SAP ≫ Business Warehouse Version 751
SAP ≫ Business Warehouse Version 752
SAP ≫ Business Warehouse Version 753
SAP ≫ Business Warehouse Version 754
SAP ≫ Business Warehouse Version 755
SAP ≫ Business Warehouse Version 756
SAP ≫ Business Warehouse Version 757
SAP ≫ Business Warehouse Version 758
SAP ≫ Business Warehouse Virtual Comp Version 701
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.24% | 0.148 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| SAP | 5.4 | 2.3 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
https://url.sap/sapsecuritypatchday
https://me.sap.com/notes/3482217