CVE-2024-21738: Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver ABAP Application Server and ABAP Platform
SAP NetWeaver ABAP Application Server and ABAP Platform do not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. An attacker with low privileges can cause limited impact to confidentiality of the application data after successful exploitation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-21738?
CVE-2024-21738 is classified as a moderate severity vulnerability due to potential limited impact on confidentiality.
How do I fix CVE-2024-21738?
To fix CVE-2024-21738, apply the latest patches and updates provided by SAP for the affected versions of the NetWeaver Application Server for ABAP.
Which versions of SAP NetWeaver ABAP are affected by CVE-2024-21738?
CVE-2024-21738 affects SAP NetWeaver ABAP versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 758, and 793.
What type of vulnerability is CVE-2024-21738?
CVE-2024-21738 is a Cross-Site Scripting (XSS) vulnerability caused by insufficient encoding of user-controlled inputs.
What impact can CVE-2024-21738 have on my application?
Exploiting CVE-2024-21738 could allow an attacker with low privileges to affect the confidentiality of application data.