CVE-2024-24742
Cross-Site Scripting (XSS) vulnerability in SAP CRM (WebClient UI)
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
SAP CRM WebClient UI - version S4FND 102, S4FND 103, S4FND 104, S4FND 105, S4FND 106, WEBCUIF 701, WEBCUIF 731, WEBCUIF 746, WEBCUIF 747, WEBCUIF 748, WEBCUIF 800, WEBCUIF 801, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. An attacker with low privileges can cause limited impact to integrity of the application data after successful exploitation. There is no impact on confidentiality and availability.
UI de SAP CRM WebClient: versión S4FND 102, S4FND 103, S4FND 104, S4FND 105, S4FND 106, WEBCUIF 701, WEBCUIF 731, WEBCUIF 746, WEBCUIF 747, WEBCUIF 748, WEBCUIF 800, WEBCUIF 801, no codifica suficientemente las entradas controladas por el usuario , lo que resulta en una vulnerabilidad de Cross-Site Scripting (XSS). Un atacante con pocos privilegios puede causar un impacto limitado en la integridad de los datos de la aplicación después de una explotación exitosa. No hay ningún impacto en la confidencialidad y la disponibilidad.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2024-01-29 CVE Reserved
- 2024-02-13 CVE Published
- 2024-08-01 CVE Updated
- 2024-10-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://me.sap.com/notes/3158455 | ||
https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
SAP SE Search vendor "SAP SE" | SAP CRM (WebClient UI) Search vendor "SAP SE" for product "SAP CRM (WebClient UI)" | 701 Search vendor "SAP SE" for product "SAP CRM (WebClient UI)" and version "701" | en |
Affected
| ||||||
SAP SE Search vendor "SAP SE" | SAP CRM (WebClient UI) Search vendor "SAP SE" for product "SAP CRM (WebClient UI)" | 731 Search vendor "SAP SE" for product "SAP CRM (WebClient UI)" and version "731" | en |
Affected
| ||||||
SAP SE Search vendor "SAP SE" | SAP CRM (WebClient UI) Search vendor "SAP SE" for product "SAP CRM (WebClient UI)" | 746 Search vendor "SAP SE" for product "SAP CRM (WebClient UI)" and version "746" | en |
Affected
| ||||||
SAP SE Search vendor "SAP SE" | SAP CRM (WebClient UI) Search vendor "SAP SE" for product "SAP CRM (WebClient UI)" | 747 Search vendor "SAP SE" for product "SAP CRM (WebClient UI)" and version "747" | en |
Affected
| ||||||
SAP SE Search vendor "SAP SE" | SAP CRM (WebClient UI) Search vendor "SAP SE" for product "SAP CRM (WebClient UI)" | 748 Search vendor "SAP SE" for product "SAP CRM (WebClient UI)" and version "748" | en |
Affected
| ||||||
SAP SE Search vendor "SAP SE" | SAP CRM (WebClient UI) Search vendor "SAP SE" for product "SAP CRM (WebClient UI)" | 800 Search vendor "SAP SE" for product "SAP CRM (WebClient UI)" and version "800" | en |
Affected
| ||||||
SAP SE Search vendor "SAP SE" | SAP CRM (WebClient UI) Search vendor "SAP SE" for product "SAP CRM (WebClient UI)" | 801 Search vendor "SAP SE" for product "SAP CRM (WebClient UI)" and version "801" | en |
Affected
|