SAP NetWeaver Application Server for ABAP and ABAP Platform do not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
An attacker can control code that is executed within a user’s browser, which could result in modification, deletion of data, including accessing or deleting files, or stealing session cookies which an attacker could use to hijack a user’s session. Hence, this could have impact on Confidentiality, Integrity and Availability of the system.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: sap
Published: 2024-05-14T03:56:24.324Z
Updated: 2024-08-02T02:59:22.228Z
Reserved: 2024-05-07T05:46:11.658Z
Link: CVE-2024-34687
Vulnrichment
Updated: 2024-08-02T02:59:22.228Z
NVD
Status : Awaiting Analysis
Published: 2024-05-14T16:17:26.143
Modified: 2024-05-14T19:17:55.627
Link: CVE-2024-34687
Redhat
No data.