The SAP Application Interface (Message Dashboard) - versions AIF 703, AIFX 702, S4CORE 100, 101, SAP_BASIS 755, 756, SAP_ABA 75C, 75D, 75E, application allows the usage HTML tags. An authorized attacker can use some of the basic HTML codes such as heading, basic formatting and lists, then an attacker can inject images from the foreign domains. After successful exploitations, an attacker can cause limited impact on the confidentiality and integrity of the application.
                
            References
                    | Link | Resource | 
|---|---|
| https://launchpad.support.sap.com/#/notes/3113349 | Permissions Required | 
| https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html | Vendor Advisory | 
| https://launchpad.support.sap.com/#/notes/3113349 | Permissions Required | 
| https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html | Vendor Advisory | 
Configurations
                    Configuration 1 (hide)
            
            
  | 
    
History
                    21 Nov 2024, 07:56
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://launchpad.support.sap.com/#/notes/3113349 - Permissions Required | |
| References | () https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html - Vendor Advisory | |
| CVSS | 
        v2 :  v3 :  | 
    
        v2 : unknown
         v3 : 3.7  | 
18 Apr 2023, 01:54
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2023-04-11 04:16
Updated : 2024-11-21 07:56
NVD link : CVE-2023-29110
Mitre link : CVE-2023-29110
CVE.ORG link : CVE-2023-29110
JSON object : View
Products Affected
                sap
- s4core
 - basis
 - application_interface_framework
 - abap_platform
 
