The SAP Application Interface (Message Dashboard) - versions AIF 703, AIFX 702, S4CORE 100, 101, SAP_BASIS 755, 756, SAP_ABA 75C, 75D, 75E, application allows the usage HTML tags. An authorized attacker can use some of the basic HTML codes such as heading, basic formatting and lists, then an attacker can inject images from the foreign domains. After successful exploitations, an attacker can cause limited impact on the confidentiality and integrity of the application.
References
Link | Resource |
---|---|
https://launchpad.support.sap.com/#/notes/3113349 | Permissions Required |
https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
18 Apr 2023, 01:54
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-04-11 04:16
Updated : 2024-02-04 23:37
NVD link : CVE-2023-29110
Mitre link : CVE-2023-29110
CVE.ORG link : CVE-2023-29110
JSON object : View
Products Affected
sap
- basis
- application_interface_framework
- s4core
- abap_platform