CVE-2024-27902: Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS ABAP applications based on SAPGUI for HTML (WebGUI)
Applications based on SAP GUI for HTML in SAP NetWeaver AS ABAP - versions 7.89, 7.93, do not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. A successful attack can allow a malicious attacker to access and modify data through their ability to execute code in a user’s browser. There is no impact on the availability of the system
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-27902?
CVE-2024-27902 has a high severity rating due to its potential for Cross-Site Scripting (XSS) attacks.
How do I fix CVE-2024-27902?
To fix CVE-2024-27902, ensure you apply the latest security patches from SAP for the affected versions of SAP NetWeaver AS ABAP.
What systems are affected by CVE-2024-27902?
CVE-2024-27902 affects SAP NetWeaver AS ABAP versions 7.89 and 7.93.
What type of vulnerability is CVE-2024-27902?
CVE-2024-27902 is a Cross-Site Scripting (XSS) vulnerability caused by insufficient encoding of user-controlled inputs.
What can attackers do if they exploit CVE-2024-27902?
If exploited, attackers can potentially access and modify sensitive data within the affected SAP applications.