First published: Tue May 14 2024(Updated: )
Document Service handler (obsolete) in Data Provisioning Service does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability with low impact on Confidentiality and Integrity of the application.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP S/4HANA Sales |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-33002 has a low impact on the Confidentiality and Integrity of the application.
To fix CVE-2024-33002, ensure that user-controlled inputs are properly encoded in the Document Service handler.
CVE-2024-33002 affects SAP S/4HANA, specifically the Document Service handler within the Data Provisioning Service.
CVE-2024-33002 is a Cross-Site Scripting (XSS) vulnerability.
Yes, CVE-2024-33002 remains relevant for current installations of SAP S/4HANA until properly patched.