PT-2024-3898 · Sap · Sap Crm Webclient Ui
Published
2024-02-12
·
Updated
2024-10-16
·
CVE-2024-24742
CVSS v3.1
4.1
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
SAP CRM WebClient UI versions S4FND 102 through S4FND 106
SAP CRM WebClient UI versions WEBCUIF 701 through WEBCUIF 801
Description:
The SAP CRM WebClient UI does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) issue. An attacker with low privileges can cause limited impact to the integrity of the application data after successful exploitation. There is no impact on confidentiality and availability. The vulnerability exists due to a lack of protection of the web page structure, allowing a remote attacker to conduct an XSS attack.
Recommendations:
For SAP CRM WebClient UI versions S4FND 102 through S4FND 106, update to a version that includes the fix for this issue.
For SAP CRM WebClient UI versions WEBCUIF 701 through WEBCUIF 801, update to a version that includes the fix for this issue.
As a temporary workaround, consider restricting access to the vulnerable UI components until a patch is available.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Crm Webclient Ui