CVE-2024-34685

CVSS V2 None CVSS V3 None
Description
Due to weak encoding of user-controlled input in SAP NetWeaver Knowledge Management XMLEditor which allows malicious scripts can be executed in the application, potentially leading to a Cross-Site Scripting (XSS) vulnerability. This has no impact on the availability of the application but it has a low impact on its confidentiality and integrity.
Overview
  • CVE ID
  • CVE-2024-34685
  • Assigner
  • sap
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-07-09T03:53:38.517Z
  • Last Modified Date
  • 2024-07-09T03:53:38.517Z
History
Created Old Value New Value Data Type Notes
2024-07-09 13:15:50 Added to TrackCVE