PT-2023-22160 · Sap · Sap Application Interface

Published

2023-04-11

·

Updated

2023-04-18

·

CVE-2023-29112

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SAP Application Interface (Message Monitoring) versions 600, 700
Description The issue allows an authorized attacker to input links or headings with custom CSS classes into a comment, which will render links and custom CSS classes as HTML objects. After successful exploitation, an attacker can cause limited impact on the confidentiality and integrity of the application.
Recommendations For versions 600 and 700, consider restricting the ability to input custom CSS classes into comments to minimize the risk of exploitation. As a temporary workaround, consider disabling the rendering of HTML objects in comments until a patch is available. Restrict access to the comment feature in the SAP Application Interface (Message Monitoring) to authorized personnel only to reduce the risk of exploitation.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-29112

Affected Products

Sap Application Interface