Due to insufficient input validation, CRM Blueprint Application Builder Panel of SAP NetWeaver Application Server for ABAP allows an unauthenticated attacker to craft a URL link which could embed a malicious JavaScript. When a victim clicks on this link, the script will be executed in the victim's browser giving the attacker the ability to access and/or modify information with no effect on availability of the application.
Metrics
Affected Vendors & Products
References
History
Tue, 10 Sep 2024 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 10 Sep 2024 04:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Due to insufficient input validation, CRM Blueprint Application Builder Panel of SAP NetWeaver Application Server for ABAP allows an unauthenticated attacker to craft a URL link which could embed a malicious JavaScript. When a victim clicks on this link, the script will be executed in the victim's browser giving the attacker the ability to access and/or modify information with no effect on availability of the application. | |
Title | Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server for ABAP (CRM Blueprint Application Builder Panel) | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: sap
Published: 2024-09-10T04:29:45.830Z
Updated: 2024-09-10T13:20:33.379Z
Reserved: 2024-08-26T10:39:20.932Z
Link: CVE-2024-45279
Vulnrichment
Updated: 2024-09-10T13:20:29.958Z
NVD
Status : Awaiting Analysis
Published: 2024-09-10T05:15:11.620
Modified: 2024-09-10T12:09:50.377
Link: CVE-2024-45279
Redhat
No data.