CVE-2024-21738
MEDIUMSAP NetWeaver ABAP Application Server and ABAP Platform - Cross-Site Scripting
Title source: llmDescription
SAP NetWeaver ABAP Application Server and ABAP Platform do not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. An attacker with low privileges can cause limited impact to confidentiality of the application data after successful exploitation.
References (2)
Core 2
Core References
Permissions Required
https://me.sap.com/notes/3387737
Scores
CVSS v3
4.1
EPSS
0.0020
EPSS Percentile
41.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-79
Status
published
Products (16)
sap/netweaver_application_server_abap
79
sap/netweaver_application_server_abap
700
sap/netweaver_application_server_abap
701
sap/netweaver_application_server_abap
702
sap/netweaver_application_server_abap
731
sap/netweaver_application_server_abap
740
sap/netweaver_application_server_abap
750
sap/netweaver_application_server_abap
751
sap/netweaver_application_server_abap
752
sap/netweaver_application_server_abap
753
... and 6 more
Published
Jan 09, 2024
Tracked Since
Feb 18, 2026