CVE-2023-24529: XSS
Due to lack of proper input validation, BSP application (CRMBSPFRAME) - versions 700, 701, 702, 731, 740, 750, 751, 752, 75C, 75D, 75E, 75F, 75G, 75H, allow malicious inputs from untrusted sources, which can be leveraged by an attacker to execute a Reflected Cross-Site Scripting (XSS) attack. As a result, an attacker may be able to hijack a user session, read and modify some sensitive information.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-24529?
CVE-2023-24529 is a vulnerability in SAP NetWeaver AS ABAP Business Server Pages that allows for a Reflected Cross-Site Scripting (XSS) attack.
Which software versions are affected by CVE-2023-24529?
SAP NetWeaver AS ABAP Business Server Pages versions 7.00, 7.01, 7.02, 7.31, 7.40, 7.50, 7.51, 7.52, 75c, 75d, 75e, 75f, 75g, and 75h are affected by CVE-2023-24529.
What is the severity of CVE-2023-24529?
CVE-2023-24529 has a severity rating of 6.1 (medium).
How can an attacker exploit CVE-2023-24529?
An attacker can exploit CVE-2023-24529 by providing malicious inputs from untrusted sources, which can then be used to execute a Reflected Cross-Site Scripting (XSS) attack.
Where can I find more information about CVE-2023-24529?
You can find more information about CVE-2023-24529 in the SAP Note 3282663 and the SAP security advisory document.