CVE Published: 09/07/2024 |
CVE Updated: 02/08/2024 |
CVE Year: 2024 Source: sap |
Vendor: SAP_SE |
Product: SAP Business Warehouse - Business Planning and Simulation Status : PUBLISHED
CVE-2024-39595 Description
SAP Business Warehouse - Business Planning and
Simulation application does not sufficiently encode user-controlled inputs,
resulting in Stored Cross-Site Scripting (XSS) vulnerability. This
vulnerability allows users to modify website content and on successful
exploitation, an attacker can cause low impact to the confidentiality and
integrity of the application.
Metrics
CVSS Version: 3.1 |
Base Score: 5.4 MEDIUM Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N