First published: Tue Feb 13 2024(Updated: )
SAP Companion - version <3.1.38, has a URL with parameter that could be vulnerable to XSS attack. The attacker could send a malicious link to a user that would possibly allow an attacker to retrieve the sensitive information and cause minor impact on the integrity of the web application.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Companion | <3.1.38 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-22129 is considered a moderate severity vulnerability due to its potential impact on web application integrity.
To fix CVE-2024-22129, upgrade SAP Companion to a version higher than 3.1.38.
CVE-2024-22129 is associated with a Cross-Site Scripting (XSS) attack that can be exploited through malicious URLs.
An attacker exploiting CVE-2024-22129 could potentially retrieve sensitive information from users.
SAP Companion versions prior to 3.1.38 are affected by CVE-2024-22129.