Beveiligingsadvies

CVE-2024-32733

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2024-05-14 03:38:19
Laatst bijgewerkt 2024-08-02 02:20:35
Toegewezen door sap
CVSS-score 6.1
Status PUBLISHED

Beschrijving

Due to missing input validation and output encoding of untrusted data, SAP NetWeaver Application Server ABAP and ABAP Platform allows an unauthenticated attacker to inject malicious JavaScript code into the dynamically crafted web page. On successful exploitation the attacker can access or modify sensitive information with no impact on availability of the application