PT-2024-24819 · Sap · Sap Netweaver Application Server Abap+1

Published

2024-05-14

·

Updated

2024-07-07

·

CVE-2024-32733

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SAP NetWeaver Application Server ABAP and ABAP Platform versions prior to 796
Description The issue is caused by missing input validation and output encoding of untrusted data, allowing an unauthenticated attacker to inject malicious JavaScript code into dynamically crafted web pages. Successful exploitation enables the attacker to access or modify sensitive information without impacting the application's availability. An attacker could remotely exploit this to hijack user sessions.
Recommendations For SAP NetWeaver Application Server ABAP and ABAP Platform versions prior to 796, update to a version that includes the necessary security patches to mitigate the risk of Cross-Site Scripting attacks. As a temporary workaround, consider restricting access to sensitive information and implementing additional security measures to protect against session hijacking.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-32733

Affected Products

Abap Platform
Sap Netweaver Application Server Abap