CVE-2023-29110

LOW

SAP ABAP Platform - Cross-Site Scripting via HTML Tag Injection

Title source: llm
STIX 2.1

Description

The SAP Application Interface (Message Dashboard) - versions AIF 703, AIFX 702, S4CORE 100, 101, SAP_BASIS 755, 756, SAP_ABA 75C, 75D, 75E, application allows the usage HTML tags. An authorized attacker can use some of the basic HTML codes such as heading, basic formatting and lists, then an attacker can inject images from the foreign domains. After successful exploitations, an attacker can cause limited impact on the confidentiality and integrity of the application.

Scores

CVSS v3 3.7
EPSS 0.0040
EPSS Percentile 61.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-80 CWE-79
Status published
Products (9)
sap/abap_platform 75c
sap/abap_platform 75d
sap/abap_platform 75e
sap/application_interface_framework aif_703
sap/application_interface_framework aifx_702
sap/basis 755
sap/basis 756
sap/s4core 100
sap/s4core 101
Published Apr 11, 2023
Tracked Since Feb 18, 2026