CVE-2024-37174
[Multiple CVEs] Multiple vulnerabilities in SAP CRM (WebClient UI)
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Custom CSS support option in SAP CRM WebClient
UI does not sufficiently encode user-controlled inputs resulting in Cross-Site
Scripting vulnerability. On successful exploitation an attacker can cause
limited impact on confidentiality and integrity of the application.
La opción de soporte CSS personalizado en la interfaz de usuario de SAP CRM WebClient no codifica suficientemente las entradas controladas por el usuario, lo que genera una vulnerabilidad de Cross Site Scripting. Si se explota con éxito, un atacante puede causar un impacto limitado en la confidencialidad y la integridad de la aplicación.
Custom CSS support option in SAP CRM WebClient UI does not sufficiently encode user-controlled inputs resulting in Cross-Site Scripting vulnerability. On successful exploitation an attacker can cause limited impact on confidentiality and integrity of the application.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2024-06-04 CVE Reserved
- 2024-07-09 CVE Published
- 2024-08-02 CVE Updated
- 2024-08-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (2)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
SAP SE Search vendor "SAP SE" | SAP CRM WebClient UI Search vendor "SAP SE" for product "SAP CRM WebClient UI" | 701 Search vendor "SAP SE" for product "SAP CRM WebClient UI" and version "701" | en |
Affected
| ||||||
SAP SE Search vendor "SAP SE" | SAP CRM WebClient UI Search vendor "SAP SE" for product "SAP CRM WebClient UI" | 731 Search vendor "SAP SE" for product "SAP CRM WebClient UI" and version "731" | en |
Affected
| ||||||
SAP SE Search vendor "SAP SE" | SAP CRM WebClient UI Search vendor "SAP SE" for product "SAP CRM WebClient UI" | 746 Search vendor "SAP SE" for product "SAP CRM WebClient UI" and version "746" | en |
Affected
| ||||||
SAP SE Search vendor "SAP SE" | SAP CRM WebClient UI Search vendor "SAP SE" for product "SAP CRM WebClient UI" | 747 Search vendor "SAP SE" for product "SAP CRM WebClient UI" and version "747" | en |
Affected
| ||||||
SAP SE Search vendor "SAP SE" | SAP CRM WebClient UI Search vendor "SAP SE" for product "SAP CRM WebClient UI" | 748 Search vendor "SAP SE" for product "SAP CRM WebClient UI" and version "748" | en |
Affected
| ||||||
SAP SE Search vendor "SAP SE" | SAP CRM WebClient UI Search vendor "SAP SE" for product "SAP CRM WebClient UI" | 800 Search vendor "SAP SE" for product "SAP CRM WebClient UI" and version "800" | en |
Affected
| ||||||
SAP SE Search vendor "SAP SE" | SAP CRM WebClient UI Search vendor "SAP SE" for product "SAP CRM WebClient UI" | 801 Search vendor "SAP SE" for product "SAP CRM WebClient UI" and version "801" | en |
Affected
|