PT-2023-3744 · Sap · Sap Netweaver

Published

2023-06-13

·

Updated

2023-06-20

·

CVE-2023-33984

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SAP NetWeaver (Design Time Repository) version 7.50
Description The issue exists due to insufficient protection of the web page structure, allowing a remote attacker to inject arbitrary HTML code. This could enable an authorized attacker to create a file with malicious content and send a link to a victim via email or instant message, potentially leading to a Cross-Site Scripting vulnerability under certain circumstances.
Recommendations For SAP NetWeaver (Design Time Repository) version 7.50, consider restricting access to versioned files to minimize the risk of exploitation until a patch is available. As a temporary workaround, avoid using the affected content types for sensitive files.

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2023-04032
CVE-2023-33984

Affected Products

Sap Netweaver