First published: Tue Sep 10 2024(Updated: )
SAP NetWeaver Enterprise Portal is vulnerable to reflected cross site scripting due to insufficient encoding of user-controlled input. An unauthenticated attacker could craft a malicious URL and trick a user to click it. If the victim clicks on this crafted URL before it times out, then the attacker could read and manipulate user content in the browser.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP NetWeaver (Enterprise Portal) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-44120 is classified as medium due to its potential for reflected cross-site scripting attacks.
To fix CVE-2024-44120, you should apply the latest security patches provided by SAP for the NetWeaver Enterprise Portal.
CVE-2024-44120 is associated with reflected cross-site scripting (XSS) attacks.
Any user of the SAP NetWeaver Enterprise Portal who clicks on a malicious URL could be affected by CVE-2024-44120.
No, CVE-2024-44120 can be exploited by unauthenticated attackers who trick victims into clicking a crafted URL.