CVE-2024-22128 Information

Description

SAP NWBC for HTML - versions SAP_UI 754 SAP_UI 755 SAP_UI 756 SAP_UI 757 SAP_UI 758 SAP_BASIS 700 SAP_BASIS 701 SAP_BASIS 702 SAP_BASIS 731 does not sufficiently encode user-controlled inputs resulting in Cross-Site Scripting (XSS) vulnerability. An unauthenticated attacker can inject malicious javascript to cause limited impact to confidentiality and integrity of the application data after successful exploitation.

Reference

https://me.sap.com/notes/3396109 https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html

Share on: