CVE-2024-37173: [Multiple CVEs] Multiple vulnerabilities in SAP CRM (WebClient UI)
Due to insufficient input validation, SAP CRM WebClient UI allows an unauthenticated attacker to craft a URL link which embeds a malicious script. When a victim clicks on this link, the script will be executed in the victim's browser giving the attacker the ability to access and/or modify information with no effect on availability of the application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-37173?
CVE-2024-37173 is considered to have a high severity due to its potential to allow unauthorized script execution in the victim's browser.
How do I fix CVE-2024-37173?
To mitigate CVE-2024-37173, apply the latest security patches provided by SAP for affected versions.
What versions of SAP CRM are affected by CVE-2024-37173?
CVE-2024-37173 affects SAP Customer Relationship Management versions 102 through 108 and specific versions of SAP CRM WebClient UI.
How does CVE-2024-37173 exploit software vulnerabilities?
CVE-2024-37173 exploits insufficient input validation to allow an attacker to execute malicious scripts through crafted URLs.
Who is at risk from CVE-2024-37173?
Users of SAP CRM WebClient UI who are tricked into clicking malicious links are at risk from CVE-2024-37173.