SAP NWBC for HTML - versions SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, SAP_UI 758, SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. An unauthenticated attacker can inject malicious javascript to cause limited impact to confidentiality and integrity of the application data after successful exploitation.
Metrics
Affected Vendors & Products
References
History
Wed, 16 Oct 2024 22:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Sap
Sap netweaver Business Client For Html |
|
CPEs | cpe:2.3:a:sap:netweaver_business_client_for_html:sap_basis_700:*:*:*:*:*:*:* cpe:2.3:a:sap:netweaver_business_client_for_html:sap_basis_701:*:*:*:*:*:*:* cpe:2.3:a:sap:netweaver_business_client_for_html:sap_basis_702:*:*:*:*:*:*:* cpe:2.3:a:sap:netweaver_business_client_for_html:sap_basis_731:*:*:*:*:*:*:* cpe:2.3:a:sap:netweaver_business_client_for_html:sap_ui_754:*:*:*:*:*:*:* cpe:2.3:a:sap:netweaver_business_client_for_html:sap_ui_755:*:*:*:*:*:*:* cpe:2.3:a:sap:netweaver_business_client_for_html:sap_ui_756:*:*:*:*:*:*:* cpe:2.3:a:sap:netweaver_business_client_for_html:sap_ui_757:*:*:*:*:*:*:* cpe:2.3:a:sap:netweaver_business_client_for_html:sap_ui_758:*:*:*:*:*:*:* |
|
Vendors & Products |
Sap
Sap netweaver Business Client For Html |
MITRE
Status: PUBLISHED
Assigner: sap
Published: 2024-02-13T02:02:14.281Z
Updated: 2024-08-01T22:35:34.814Z
Reserved: 2024-01-05T10:21:35.256Z
Link: CVE-2024-22128
Vulnrichment
Updated: 2024-08-01T22:35:34.814Z
NVD
Status : Analyzed
Published: 2024-02-13T02:15:08.323
Modified: 2024-10-16T21:30:47.157
Link: CVE-2024-22128
Redhat
No data.