First published: Tue Jun 11 2024(Updated: )
SAP Financial Consolidation does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. These endpoints are exposed over the network. The vulnerability can exploit resources beyond the vulnerable component. On successful exploitation, an attacker can cause limited impact to confidentiality of the application.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP BusinessObjects Financial Consolidation |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-37178 is classified as a Cross-Site Scripting (XSS) vulnerability in SAP Financial Consolidation.
To mitigate CVE-2024-37178, ensure that user-controlled inputs are properly encoded before being rendered on the web application.
Exploitation of CVE-2024-37178 may allow an attacker to execute arbitrary scripts in the context of the affected user’s session.
SAP Financial Consolidation editions that do not properly encode user-controlled inputs are subject to CVE-2024-37178.
Yes, CVE-2024-37178 impacts endpoints exposed over the network, making it accessible to external threats.