First published: Tue Jan 09 2024(Updated: )
SAP NetWeaver ABAP Application Server and ABAP Platform do not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. An attacker with low privileges can cause limited impact to confidentiality of the application data after successful exploitation.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP NetWeaver Application Server | =79 | |
SAP NetWeaver Application Server | =700 | |
SAP NetWeaver Application Server | =701 | |
SAP NetWeaver Application Server | =702 | |
SAP NetWeaver Application Server | =731 | |
SAP NetWeaver Application Server | =740 | |
SAP NetWeaver Application Server | =750 | |
SAP NetWeaver Application Server | =751 | |
SAP NetWeaver Application Server | =752 | |
SAP NetWeaver Application Server | =753 | |
SAP NetWeaver Application Server | =754 | |
SAP NetWeaver Application Server | =755 | |
SAP NetWeaver Application Server | =756 | |
SAP NetWeaver Application Server | =757 | |
SAP NetWeaver Application Server | =758 | |
SAP NetWeaver Application Server | =793 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-21738 is classified as a moderate severity vulnerability due to potential limited impact on confidentiality.
To fix CVE-2024-21738, apply the latest patches and updates provided by SAP for the affected versions of the NetWeaver Application Server for ABAP.
CVE-2024-21738 affects SAP NetWeaver ABAP versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 758, and 793.
CVE-2024-21738 is a Cross-Site Scripting (XSS) vulnerability caused by insufficient encoding of user-controlled inputs.
Exploiting CVE-2024-21738 could allow an attacker with low privileges to affect the confidentiality of application data.