CVE-2024-27902

Applications based on SAP GUI for HTML in SAP NetWeaver AS ABAP - versions 7.89, 7.93, do not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. A successful attack can allow a malicious attacker to access and modify data through their ability to execute code in a user’s browser. There is no impact on the availability of the system
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sap:netweaver_as_abap:sap_ui_7.89:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_as_abap:sap_ui_7.93:*:*:*:*:*:*:*

History

26 Feb 2025, 15:15

Type Values Removed Values Added
CPE cpe:2.3:a:sap:netweaver_as_abap:sap_ui_7.89:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_as_abap:sap_ui_7.93:*:*:*:*:*:*:*
First Time Sap
Sap netweaver As Abap
References () https://me.sap.com/notes/3377979 - () https://me.sap.com/notes/3377979 - Permissions Required
References () https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html?anchorId=section_370125364 - () https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html?anchorId=section_370125364 - Vendor Advisory

21 Nov 2024, 09:05

Type Values Removed Values Added
Summary
  • (es) Las aplicaciones basadas en SAP GUI para HTML en SAP NetWeaver AS ABAP (versiones 7.89, 7.93) no codifican suficientemente las entradas controladas por el usuario, lo que genera una vulnerabilidad de cross-site scripting (XSS). Un ataque exitoso puede permitir que un atacante malintencionado acceda y modifique datos a través de su capacidad para ejecutar código en el navegador de un usuario. No hay impacto en la disponibilidad del sistema.
References () https://me.sap.com/notes/3377979 - () https://me.sap.com/notes/3377979 -
References () https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html?anchorId=section_370125364 - () https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html?anchorId=section_370125364 -

12 Mar 2024, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-12 01:15

Updated : 2025-02-26 15:15


NVD link : CVE-2024-27902

Mitre link : CVE-2024-27902

CVE.ORG link : CVE-2024-27902


JSON object : View

Products Affected

sap

  • netweaver_as_abap
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')