PT-2024-24819 · Sap · Sap Netweaver Application Server Abap+1
Published
2024-05-14
·
Updated
2024-07-07
·
CVE-2024-32733
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
SAP NetWeaver Application Server ABAP and ABAP Platform versions prior to 796
Description
The issue is caused by missing input validation and output encoding of untrusted data, allowing an unauthenticated attacker to inject malicious JavaScript code into dynamically crafted web pages. Successful exploitation enables the attacker to access or modify sensitive information without impacting the application's availability. An attacker could remotely exploit this to hijack user sessions.
Recommendations
For SAP NetWeaver Application Server ABAP and ABAP Platform versions prior to 796, update to a version that includes the necessary security patches to mitigate the risk of Cross-Site Scripting attacks. As a temporary workaround, consider restricting access to sensitive information and implementing additional security measures to protect against session hijacking.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Abap Platform
Sap Netweaver Application Server Abap