CVE-2024-47594Cross-site Scripting in SE SAP Netweaver Enterprise Portal

Severity
5.4MEDIUMNVD
EPSS
0.6%
top 30.10%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 8

Description

SAP NetWeaver Enterprise Portal (KMC) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting vulnerability in KMC servlet. An attacker could craft a script and trick the user into clicking it. When a victim who is registered on the portal clicks on such link, confidentiality and integrity of their web browser session could be compromised.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages2 packages

🔴Vulnerability Details

2
CVEList
Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal (KMC)2024-10-08
GHSA
GHSA-wfxp-9533-q68r: SAP NetWeaver Enterprise Portal (KMC) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting vulnerability in KMC serv2024-10-08
CVE-2024-47594 — Cross-site Scripting | cvebase