SAP Business Warehouse - Business Planning and
Simulation application does not sufficiently encode user-controlled inputs,
resulting in Stored Cross-Site Scripting (XSS) vulnerability. This
vulnerability allows users to modify website content and on successful
exploitation, an attacker can cause low impact to the confidentiality and
integrity of the application.
Simulation application does not sufficiently encode user-controlled inputs,
resulting in Stored Cross-Site Scripting (XSS) vulnerability. This
vulnerability allows users to modify website content and on successful
exploitation, an attacker can cause low impact to the confidentiality and
integrity of the application.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-38115 | SAP Business Warehouse - Business Planning and Simulation application does not sufficiently encode user-controlled inputs, resulting in Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability allows users to modify website content and on successful exploitation, an attacker can cause low impact to the confidentiality and integrity of the application. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 28 Oct 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sap
Sap business Warehouse Sap business Warehouse Virtual Comp |
|
| CPEs | cpe:2.3:a:sap:business_warehouse:700:*:*:*:*:*:*:* cpe:2.3:a:sap:business_warehouse:701:*:*:*:*:*:*:* cpe:2.3:a:sap:business_warehouse:702:*:*:*:*:*:*:* cpe:2.3:a:sap:business_warehouse:730:*:*:*:*:*:*:* cpe:2.3:a:sap:business_warehouse:731:*:*:*:*:*:*:* cpe:2.3:a:sap:business_warehouse:740:*:*:*:*:*:*:* cpe:2.3:a:sap:business_warehouse:750:*:*:*:*:*:*:* cpe:2.3:a:sap:business_warehouse:751:*:*:*:*:*:*:* cpe:2.3:a:sap:business_warehouse:752:*:*:*:*:*:*:* cpe:2.3:a:sap:business_warehouse:753:*:*:*:*:*:*:* cpe:2.3:a:sap:business_warehouse:754:*:*:*:*:*:*:* cpe:2.3:a:sap:business_warehouse:755:*:*:*:*:*:*:* cpe:2.3:a:sap:business_warehouse:756:*:*:*:*:*:*:* cpe:2.3:a:sap:business_warehouse:757:*:*:*:*:*:*:* cpe:2.3:a:sap:business_warehouse:758:*:*:*:*:*:*:* cpe:2.3:a:sap:business_warehouse_virtual_comp:701:*:*:*:*:*:*:* |
|
| Vendors & Products |
Sap
Sap business Warehouse Sap business Warehouse Virtual Comp |
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2024-08-02T04:26:16.023Z
Reserved: 2024-06-26T09:58:24.095Z
Link: CVE-2024-39595
Updated: 2024-07-09T14:54:00.406Z
Status : Analyzed
Published: 2024-07-09T05:15:12.507
Modified: 2025-10-28T18:41:39.603
Link: CVE-2024-39595
No data.
OpenCVE Enrichment
No data.
EUVD