SAP NWBC for HTML - versions SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, SAP_UI 758, SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. An unauthenticated attacker can inject malicious javascript to cause limited impact to confidentiality and integrity of the application data after successful exploitation.
2024-02-13T02:15:08.323
2024-11-21T08:55:38.297
Modified
CVSSv3.1: 4.7 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | sap | netweaver_business_client_for_html | sap_basis_700 | Yes |
Application | sap | netweaver_business_client_for_html | sap_basis_701 | Yes |
Application | sap | netweaver_business_client_for_html | sap_basis_702 | Yes |
Application | sap | netweaver_business_client_for_html | sap_basis_731 | Yes |
Application | sap | netweaver_business_client_for_html | sap_ui_754 | Yes |
Application | sap | netweaver_business_client_for_html | sap_ui_755 | Yes |
Application | sap | netweaver_business_client_for_html | sap_ui_756 | Yes |
Application | sap | netweaver_business_client_for_html | sap_ui_757 | Yes |
Application | sap | netweaver_business_client_for_html | sap_ui_758 | Yes |