CVE-2023-40624: Code Injection vulnerability in SAP NetWeaver AS ABAP (applications based on Unified Rendering)
SAP NetWeaver AS ABAP (applications based on Unified Rendering) - versions SAPUI 754, SAPUI 755, SAPUI 756, SAPUI 757, SAPUI 758, SAPBASIS 702, SAPBASIS 731, allows an attacker to inject JavaScript code that can be executed in the web-application. An attacker could thereby control the behavior of this web-application.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2023-40624.
What is the severity level of CVE-2023-40624?
CVE-2023-40624 has a severity level of medium.
Which versions of SAP NetWeaver AS ABAP are affected by CVE-2023-40624?
The affected versions of SAP NetWeaver AS ABAP are SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, and SAP_UI 758, as well as SAP_BASIS 702 and SAP_BASIS 731.
What is the type of vulnerability in CVE-2023-40624?
The type of vulnerability in CVE-2023-40624 is the injection of JavaScript code that can be executed in the web application.
How can an attacker exploit CVE-2023-40624?
An attacker can exploit CVE-2023-40624 by injecting malicious JavaScript code to control the behavior of the web application.