CVE-2024-22128 Information
Feb 14, 2024
cve
Description
SAP NWBC for HTML - versions SAP_UI 754 SAP_UI 755 SAP_UI 756 SAP_UI 757 SAP_UI 758 SAP_BASIS 700 SAP_BASIS 701 SAP_BASIS 702 SAP_BASIS 731 does not sufficiently encode user-controlled inputs resulting in Cross-Site Scripting (XSS) vulnerability. An unauthenticated attacker can inject malicious javascript to cause limited impact to confidentiality and integrity of the application data after successful exploitation.
Reference
https://me.sap.com/notes/3396109 https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html
Share on: