Under certain conditions, ABAP Online Community in SAP NetWeaver (SAP_BASIS version 7.40) and SAP S/4HANA (SAP_BASIS versions 7.50, 7.51, 7.52, 7.53, 7.54), does not sufficiently encode user-controlled inputs, resulting in Reflected Cross-Site Scripting (XSS) vulnerability.
2020-02-12T20:15:13.997
2024-11-21T05:35:15.393
Modified
CVSSv3.1: 6.1 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:P/A:N
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | sap | netweaver | 7.40 | Yes |
Application | sap | s\/4hana | 7.50 | Yes |
Application | sap | s\/4hana | 7.51 | Yes |
Application | sap | s\/4hana | 7.52 | Yes |
Application | sap | s\/4hana | 7.53 | Yes |
Application | sap | s\/4hana | 7.54 | Yes |