CVE-2023-29112
LOWSAP Application Interface (Message Monitoring) -600,700 - XSS
Title source: llmDescription
The SAP Application Interface (Message Monitoring) - versions 600, 700, allows an authorized attacker to input links or headings with custom CSS classes into a comment. The comment will render links and custom CSS classes as HTML objects. After successful exploitations, an attacker can cause limited impact on the confidentiality and integrity of the application.
References (2)
Core 2
Core References
Permissions Required
https://launchpad.support.sap.com/#/notes/3114489
Scores
CVSS v3
3.7
EPSS
0.0040
EPSS Percentile
61.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-80
CWE-79
Status
published
Products (2)
sap/application_interface
600
sap/application_interface
700
Published
Apr 11, 2023
Tracked Since
Feb 18, 2026