CVE-2024-47590

HIGH

SAP Web Dispatcher - Unauthenticated Cross-Site Scripting and Server-Side Request Forgery via Malicious Link

Title source: llm
STIX 2.1

Description

An unauthenticated attacker can create a malicious link which they can make publicly available. When an authenticated victim clicks on this malicious link, input data will be used by the web site page generation to create content which when executed in the victim's browser (XXS) or transmitted to another server (SSRF) gives the attacker the ability to execute arbitrary code on the server fully compromising confidentiality, integrity and availability.

References (2)

Core 2
Core References

Scores

CVSS v3 8.8
EPSS 0.0071
EPSS Percentile 72.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-791
Status published
Products (6)
SAP_SE/SAP Web Dispatcher 7.89
SAP_SE/SAP Web Dispatcher 7.93
SAP_SE/SAP Web Dispatcher 9.12
SAP_SE/SAP Web Dispatcher 9.13
SAP_SE/SAP Web Dispatcher KERNEL 7.77
SAP_SE/SAP Web Dispatcher WEBDISP 7.77
Published Nov 12, 2024
Tracked Since Feb 18, 2026