PT-2023-3744 · Sap · Sap Netweaver
Published
2023-06-13
·
Updated
2023-06-20
·
CVE-2023-33984
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
SAP NetWeaver (Design Time Repository) version 7.50
Description
The issue exists due to insufficient protection of the web page structure, allowing a remote attacker to inject arbitrary HTML code. This could enable an authorized attacker to create a file with malicious content and send a link to a victim via email or instant message, potentially leading to a Cross-Site Scripting vulnerability under certain circumstances.
Recommendations
For SAP NetWeaver (Design Time Repository) version 7.50, consider restricting access to versioned files to minimize the risk of exploitation until a patch is available. As a temporary workaround, avoid using the affected content types for sensitive files.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Netweaver