Description
Due to insufficient encoding of user-controlled inputs, SAP NetWeaver AS Java allows malicious scripts to be executed in the login application. This has a limited impact on confidentiality and integrity of the application. There is no impact on availability.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-41412 | Due to insufficient encoding of user-controlled inputs, SAP NetWeaver AS Java allows malicious scripts to be executed in the login application. This has a limited impact on confidentiality and integrity of the application. There is no impact on availability. |
References
History
Tue, 17 Sep 2024 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 10 Sep 2024 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Due to insufficient encoding of user-controlled inputs, SAP NetWeaver AS Java allows malicious scripts to be executed in the login application. This has a limited impact on confidentiality and integrity of the application. There is no impact on availability. | |
| Title | Cross-Site Scripting (XSS) Vulnerability in SAP NetWeaver AS Java (Logon Application) | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2024-09-16T16:16:44.927Z
Reserved: 2024-08-26T10:39:20.932Z
Link: CVE-2024-45280
Updated: 2024-09-10T13:19:57.753Z
Status : Awaiting Analysis
Published: 2024-09-10T05:15:11.810
Modified: 2024-09-10T12:09:50.377
Link: CVE-2024-45280
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD