An unauthenticated attacker can create a malicious link which they can make publicly available. When an authenticated victim clicks on this malicious link, input data will be used by the web site page generation to create content which when executed in the victim's browser (XXS) or transmitted to another server (SSRF) gives the attacker the ability to execute arbitrary code on the server fully compromising confidentiality, integrity and availability.
History

Tue, 12 Nov 2024 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Sap
Sap web Dispatcher
CPEs cpe:2.3:a:sap:web_dispatcher:7.89:*:*:*:*:*:*:*
cpe:2.3:a:sap:web_dispatcher:7.93:*:*:*:*:*:*:*
cpe:2.3:a:sap:web_dispatcher:9.12:*:*:*:*:*:*:*
cpe:2.3:a:sap:web_dispatcher:9.13:*:*:*:*:*:*:*
cpe:2.3:a:sap:web_dispatcher:kernel_7.77:*:*:*:*:*:*:*
cpe:2.3:a:sap:web_dispatcher:webdisp_7.77:*:*:*:*:*:*:*
Vendors & Products Sap
Sap web Dispatcher
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 12 Nov 2024 00:45:00 +0000

Type Values Removed Values Added
Description An unauthenticated attacker can create a malicious link which they can make publicly available. When an authenticated victim clicks on this malicious link, input data will be used by the web site page generation to create content which when executed in the victim's browser (XXS) or transmitted to another server (SSRF) gives the attacker the ability to execute arbitrary code on the server fully compromising confidentiality, integrity and availability.
Title Cross-Site Scripting (XSS) vulnerability in SAP Web Dispatcher
Weaknesses CWE-791
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published: 2024-11-12T00:26:18.659Z

Updated: 2024-11-12T17:11:38.220Z

Reserved: 2024-09-27T20:05:59.021Z

Link: CVE-2024-47590

cve-icon Vulnrichment

Updated: 2024-11-12T17:11:04.424Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-11-12T01:15:04.933

Modified: 2024-11-12T13:55:21.227

Link: CVE-2024-47590

cve-icon Redhat

No data.