Lucene search

K
cveSapCVE-2024-22128
HistoryFeb 13, 2024 - 2:15 a.m.

CVE-2024-22128

2024-02-1302:15:08
CWE-79
sap
web.nvd.nist.gov
22
cve-2024-22128
sap nwbc
html
sap_ui
sap_basis
xss
cross-site scripting
nvd
security vulnerability

CVSS3

4.7

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0

Percentile

9.0%

SAP NWBC for HTML - versions SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, SAP_UI 758, SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. An unauthenticated attacker can inject malicious javascript to cause limited impact to confidentiality and integrity of the application data after successful exploitation.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "SAP NetWeaver Business Client for HTML",
    "vendor": "SAP_SE",
    "versions": [
      {
        "status": "affected",
        "version": "SAP_UI 754"
      },
      {
        "status": "affected",
        "version": "SAP_UI 755"
      },
      {
        "status": "affected",
        "version": "SAP_UI 756"
      },
      {
        "status": "affected",
        "version": "SAP_UI 757"
      },
      {
        "status": "affected",
        "version": "SAP_UI 758"
      },
      {
        "status": "affected",
        "version": "SAP_BASIS 700"
      },
      {
        "status": "affected",
        "version": "SAP_BASIS 701"
      },
      {
        "status": "affected",
        "version": "SAP_BASIS 702"
      },
      {
        "status": "affected",
        "version": "SAP_BASIS 731"
      }
    ]
  }
]

CVSS3

4.7

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0

Percentile

9.0%

Related for CVE-2024-22128