Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-22128


SAP NWBC for HTML - versions SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, SAP_UI 758, SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. An unauthenticated attacker can inject malicious javascript to cause limited impact to confidentiality and integrity of the application data after successful exploitation.


Published

2024-02-13T02:15:08.323

Last Modified

2024-11-21T08:55:38.297

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.7 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application sap netweaver_business_client_for_html sap_basis_700 Yes
Application sap netweaver_business_client_for_html sap_basis_701 Yes
Application sap netweaver_business_client_for_html sap_basis_702 Yes
Application sap netweaver_business_client_for_html sap_basis_731 Yes
Application sap netweaver_business_client_for_html sap_ui_754 Yes
Application sap netweaver_business_client_for_html sap_ui_755 Yes
Application sap netweaver_business_client_for_html sap_ui_756 Yes
Application sap netweaver_business_client_for_html sap_ui_757 Yes
Application sap netweaver_business_client_for_html sap_ui_758 Yes

References