CVE-2024-42378
Published: Sep 10, 2024
Modified: Sep 10, 2024
CVSS v3.1
6.1
Description
Due to weak encoding of user-controlled inputs, eProcurement on SAP S/4HANA allows malicious scripts to be executed in the application, potentially leading to a Reflected Cross-Site Scripting (XSS) vulnerability. This has no impact on the availability of the application, but it can have some minor impact on its confidentiality and integrity.
| Vendor | Product | Versions |
|---|---|---|
SAP_SE | SAP S/4HANA eProcurement | affected SAP_APPL 606affected SAP_APPL 617affected SAP_APPL 618affected S4CORE 102affected S4CORE 103+5 more versions |
Weaknesses (CWE)
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now