First published: Tue Jun 11 2024(Updated: )
Due to insufficient input validation, SAP CRM WebClient UI allows an unauthenticated attacker to craft a URL link which embeds a malicious script. When a victim clicks on this link, the script will be executed in the victim's browser giving the attacker the ability to access and/or modify information with no effect on availability of the application.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP CRM - WebClient UI | =103 | |
SAP CRM - WebClient UI | =104 | |
SAP CRM - WebClient UI | =105 | |
SAP CRM - WebClient UI | =106 | |
SAP CRM - WebClient UI | =107 | |
SAP CRM - WebClient UI | =701 | |
SAP CRM - WebClient UI | =730 | |
SAP CRM - WebClient UI | =731 | |
SAP CRM - WebClient UI | =746 | |
SAP CRM - WebClient UI | =747 | |
SAP CRM - WebClient UI | =748 | |
SAP CRM - WebClient UI | =800 | |
SAP CRM - WebClient UI | =801 | |
SAP CRM - WebClient UI | =s4fnd_102 | |
SAP CRM - WebClient UI | =webcuif_700 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-34686 is rated as critical due to its potential for exploitation via cross-site scripting (XSS).
To fix CVE-2024-34686, upgrade to the latest version of SAP CRM WebClient UI that addresses the insufficient input validation issues.
CVE-2024-34686 affects specific versions of SAP CRM WebClient UI, including versions 103, 104, 105, 106, 107, and several others listed in the vulnerability report.
CVE-2024-34686 can be exploited by unauthenticated attackers who can craft malicious URLs to execute scripts in victims' browsers.
The impact of CVE-2024-34686 includes unauthorized access and manipulation of user data through executed scripts when users interact with affected links.