CVE-2024-24742: Cross-Site Scripting (XSS) vulnerability in SAP CRM (WebClient UI)
SAP CRM WebClient UI - version S4FND 102, S4FND 103, S4FND 104, S4FND 105, S4FND 106, WEBCUIF 701, WEBCUIF 731, WEBCUIF 746, WEBCUIF 747, WEBCUIF 748, WEBCUIF 800, WEBCUIF 801, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. An attacker with low privileges can cause limited impact to integrity of the application data after successful exploitation. There is no impact on confidentiality and availability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-24742?
CVE-2024-24742 has a high severity due to its Cross-Site Scripting (XSS) vulnerability affecting multiple versions of SAP CRM WebClient UI.
How do I fix CVE-2024-24742?
To fix CVE-2024-24742, ensure that user-controlled inputs are properly encoded in the affected SAP CRM WebClient UI versions.
Which SAP CRM WebClient UI versions are affected by CVE-2024-24742?
CVE-2024-24742 affects SAP CRM WebClient UI versions S4FND 102 to 106 and WEBCUIF 701 to 801.
What type of vulnerability is CVE-2024-24742?
CVE-2024-24742 is a Cross-Site Scripting (XSS) vulnerability resulting from insufficient encoding of user inputs.
Who is impacted by CVE-2024-24742?
Organizations using the specified versions of SAP CRM WebClient UI are impacted by CVE-2024-24742 due to the XSS vulnerability.