CVE-2023-33985

CVSS V2 None CVSS V3 None
Description
SAP NetWeaver Enterprise Portal - version 7.50, does not sufficiently encode user-controlled inputs over the network, resulting in reflected Cross-Site Scripting (XSS) vulnerability, therefore changing the scope of the attack. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality and integrity of the application.
Overview
  • CVE ID
  • CVE-2023-33985
  • Assigner
  • sap
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2023-06-13T02:45:00.752Z
  • Last Modified Date
  • 2023-06-13T02:45:00.752Z
History
Created Old Value New Value Data Type Notes
2024-06-25 08:00:47 Added to TrackCVE