CVE-2024-34686: Cross-Site Scripting (XSS) vulnerability in SAP CRM (WebClient UI)
Due to insufficient input validation, SAP CRM WebClient UI allows an unauthenticated attacker to craft a URL link which embeds a malicious script. When a victim clicks on this link, the script will be executed in the victim's browser giving the attacker the ability to access and/or modify information with no effect on availability of the application.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-34686?
CVE-2024-34686 is rated as critical due to its potential for exploitation via cross-site scripting (XSS).
How do I fix CVE-2024-34686?
To fix CVE-2024-34686, upgrade to the latest version of SAP CRM WebClient UI that addresses the insufficient input validation issues.
What software is affected by CVE-2024-34686?
CVE-2024-34686 affects specific versions of SAP CRM WebClient UI, including versions 103, 104, 105, 106, 107, and several others listed in the vulnerability report.
Who can exploit CVE-2024-34686?
CVE-2024-34686 can be exploited by unauthenticated attackers who can craft malicious URLs to execute scripts in victims' browsers.
What is the impact of CVE-2024-34686?
The impact of CVE-2024-34686 includes unauthorized access and manipulation of user data through executed scripts when users interact with affected links.