Lucene search

K
nvd[email protected]NVD:CVE-2023-33984
HistoryJun 13, 2023 - 3:15 a.m.

CVE-2023-33984

2023-06-1303:15:09
CWE-79
web.nvd.nist.gov
6
cve-2023-33984
sap netweaver
design time repository
cross-site scripting
unauthorized content type

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

29.6%

SAP NetWeaver (Design Time Repository) - version 7.50, returns an unfavorable content type for some versioned files, which could allow an authorized attacker to create a file with a malicious content and send a link to a victim in an email or instant message. Under certain circumstances, this could lead to Cross-Site Scripting vulnerability.

Affected configurations

Nvd
Node
sapnetweaverMatch7.50
VendorProductVersionCPE
sapnetweaver7.50cpe:2.3:a:sap:netweaver:7.50:*:*:*:*:*:*:*

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

29.6%

Related for NVD:CVE-2023-33984