CVE-2023-29112

LOW

SAP Application Interface (Message Monitoring) -600,700 - XSS

Title source: llm
STIX 2.1

Description

The SAP Application Interface (Message Monitoring) - versions 600, 700, allows an authorized attacker to input links or headings with custom CSS classes into a comment. The comment will render links and custom CSS classes as HTML objects. After successful exploitations, an attacker can cause limited impact on the confidentiality and integrity of the application.

Scores

CVSS v3 3.7
EPSS 0.0040
EPSS Percentile 61.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-80 CWE-79
Status published
Products (2)
sap/application_interface 600
sap/application_interface 700
Published Apr 11, 2023
Tracked Since Feb 18, 2026