Due to weak encoding of user-controlled inputs, eProcurement on SAP S/4HANA allows malicious scripts to be executed in the application, potentially leading to a Reflected Cross-Site Scripting (XSS) vulnerability. This has no impact on the availability of the application, but it can have some minor impact on its confidentiality and integrity.
History

Tue, 10 Sep 2024 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 10 Sep 2024 03:00:00 +0000

Type Values Removed Values Added
Description Due to weak encoding of user-controlled inputs, eProcurement on SAP S/4HANA allows malicious scripts to be executed in the application, potentially leading to a Reflected Cross-Site Scripting (XSS) vulnerability. This has no impact on the availability of the application, but it can have some minor impact on its confidentiality and integrity.
Title Cross-Site Scripting (XSS) in eProcurement on S/4HANA
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published: 2024-09-10T02:41:47.517Z

Updated: 2024-09-10T13:38:11.796Z

Reserved: 2024-07-31T04:09:36.223Z

Link: CVE-2024-42378

cve-icon Vulnrichment

Updated: 2024-09-10T13:37:50.956Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-09-10T03:15:02.443

Modified: 2024-09-10T12:09:50.377

Link: CVE-2024-42378

cve-icon Redhat

No data.