CVE-2024-22129: Cross-Site Scripting (XSS) vulnerability in SAP Companion
SAP Companion - version <3.1.38, has a URL with parameter that could be vulnerable to XSS attack. The attacker could send a malicious link to a user that would possibly allow an attacker to retrieve the sensitive information and cause minor impact on the integrity of the web application.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SAP Companionto a version that resolves this vulnerability.Fixed in 3.1.38
Event History
Frequently Asked Questions
What is the severity of CVE-2024-22129?
CVE-2024-22129 is considered a moderate severity vulnerability due to its potential impact on web application integrity.
How do I fix CVE-2024-22129?
To fix CVE-2024-22129, upgrade SAP Companion to a version higher than 3.1.38.
What type of attack is associated with CVE-2024-22129?
CVE-2024-22129 is associated with a Cross-Site Scripting (XSS) attack that can be exploited through malicious URLs.
What could an attacker gain by exploiting CVE-2024-22129?
An attacker exploiting CVE-2024-22129 could potentially retrieve sensitive information from users.
Which versions of SAP Companion are affected by CVE-2024-22129?
SAP Companion versions prior to 3.1.38 are affected by CVE-2024-22129.