CVE-2023-40624
MEDIUMSAP NetWeaver AS ABAP - Stored Cross-Site Scripting in Unified Rendering
Title source: llmDescription
SAP NetWeaver AS ABAP (applications based on Unified Rendering) - versions SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, SAP_UI 758, SAP_BASIS 702, SAP_BASIS 731, allows an attacker to inject JavaScript code that can be executed in the web-application. An attacker could thereby control the behavior of this web-application.
References (2)
Core 2
Core References
Permissions Required, Vendor Advisory
https://me.sap.com/notes/3323163
Scores
CVSS v3
5.5
EPSS
0.0011
EPSS Percentile
28.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-79
Status
published
Products (7)
sap/netweaver_application_server_abap
702
sap/netweaver_application_server_abap
731
sap/netweaver_application_server_abap
754
sap/netweaver_application_server_abap
755
sap/netweaver_application_server_abap
756
sap/netweaver_application_server_abap
757
sap/netweaver_application_server_abap
758
Published
Sep 12, 2023
Tracked Since
Feb 18, 2026