CVE-2023-37488: Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Process Integration
In SAP NetWeaver Process Integration - versions SAPXIESR 7.50, SAPXITOOL 7.50, SAPXIAF 7.50, user-controlled inputs, if not sufficiently encoded, could result in Cross-Site Scripting (XSS) attack. On successful exploitation the attacker can cause limited impact on confidentiality and integrity of the system.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-37488.
What is the severity of CVE-2023-37488?
The severity of CVE-2023-37488 is medium, with a severity value of 6.1.
Which software versions are affected by CVE-2023-37488?
The affected software version is SAP NetWeaver Process Integration 7.50.
What is the impact of CVE-2023-37488?
On successful exploitation, the attacker can cause limited impact on the confidentiality and integrity of the system.
Are there any references available for CVE-2023-37488?
Yes, you can find references at the following links: [Reference 1](https://me.sap.com/notes/3350494) and [Reference 2](https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html).