Under certain conditions ABAP Online Community in SAP NetWeaver (SAP_BASIS version 7.40) and SAP S/4HANA (SAP_BASIS versions 7.50, 7.51, 7.52, 7.53, 7.54), allows an authenticated attacker to store a malicious payload which results in Stored Cross Site Scripting vulnerability.
2020-02-12T20:15:14.120
2024-11-21T05:35:15.507
Modified
CVSSv3.1: 5.4 (MEDIUM)
AV:N/AC:M/Au:S/C:N/I:P/A:N
6.8
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | sap | netweaver | 7.40 | Yes |
Application | sap | s\/4hana | 7.50 | Yes |
Application | sap | s\/4hana | 7.51 | Yes |
Application | sap | s\/4hana | 7.52 | Yes |
Application | sap | s\/4hana | 7.53 | Yes |
Application | sap | s\/4hana | 7.54 | Yes |