First published: Tue Mar 12 2024(Updated: )
Applications based on SAP GUI for HTML in SAP NetWeaver AS ABAP - versions 7.89, 7.93, do not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. A successful attack can allow a malicious attacker to access and modify data through their ability to execute code in a user’s browser. There is no impact on the availability of the system
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP NetWeaver Application Server for ABAP | >=7.89<7.93 | |
SAP NetWeaver Application Server for ABAP | =sap_ui_7.89 | |
SAP NetWeaver Application Server for ABAP | =sap_ui_7.93 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-27902 has a high severity rating due to its potential for Cross-Site Scripting (XSS) attacks.
To fix CVE-2024-27902, ensure you apply the latest security patches from SAP for the affected versions of SAP NetWeaver AS ABAP.
CVE-2024-27902 affects SAP NetWeaver AS ABAP versions 7.89 and 7.93.
CVE-2024-27902 is a Cross-Site Scripting (XSS) vulnerability caused by insufficient encoding of user-controlled inputs.
If exploited, attackers can potentially access and modify sensitive data within the affected SAP applications.