Description
SAP NWBC for HTML - versions SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. An unauthenticated attacker can inject malicious javascript to cause limited impact to confidentiality and integrity of the application data after successful exploitation.
References (2)
Core 2
Core References
Permissions Required
https://me.sap.com/notes/3396109
Scores
CVSS v3
4.7
EPSS
0.0126
EPSS Percentile
79.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-79
Status
published
Products (9)
sap/netweaver_business_client_for_html
sap_basis_700
sap/netweaver_business_client_for_html
sap_basis_701
sap/netweaver_business_client_for_html
sap_basis_702
sap/netweaver_business_client_for_html
sap_basis_731
sap/netweaver_business_client_for_html
sap_ui_754
sap/netweaver_business_client_for_html
sap_ui_755
sap/netweaver_business_client_for_html
sap_ui_756
sap/netweaver_business_client_for_html
sap_ui_757
sap/netweaver_business_client_for_html
sap_ui_758
Published
Feb 13, 2024
Tracked Since
Feb 18, 2026