Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-37173


Due to insufficient input validation, SAP CRM WebClient UI allows an unauthenticated attacker to craft a URL link which embeds a malicious script. When a victim clicks on this link, the script will be executed in the victim's browser giving the attacker the ability to access and/or modify information with no effect on availability of the application.


Published

2024-07-09T04:15:12.867

Last Modified

2024-11-21T09:23:21.503

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.1 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application sap customer_relationship_management_s4fnd 102 Yes
Application sap customer_relationship_management_s4fnd 103 Yes
Application sap customer_relationship_management_s4fnd 104 Yes
Application sap customer_relationship_management_s4fnd 105 Yes
Application sap customer_relationship_management_s4fnd 106 Yes
Application sap customer_relationship_management_s4fnd 107 Yes
Application sap customer_relationship_management_s4fnd 108 Yes
Application sap customer_relationship_management_webclient_ui 701 Yes
Application sap customer_relationship_management_webclient_ui 731 Yes
Application sap customer_relationship_management_webclient_ui 746 Yes
Application sap customer_relationship_management_webclient_ui 747 Yes
Application sap customer_relationship_management_webclient_ui 748 Yes
Application sap customer_relationship_management_webclient_ui 800 Yes
Application sap customer_relationship_management_webclient_ui 801 Yes

References