CVE-2024-44120: Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal
SAP NetWeaver Enterprise Portal is vulnerable to reflected cross site scripting due to insufficient encoding of user-controlled input. An unauthenticated attacker could craft a malicious URL and trick a user to click it. If the victim clicks on this crafted URL before it times out, then the attacker could read and manipulate user content in the browser.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-44120?
The severity of CVE-2024-44120 is classified as medium due to its potential for reflected cross-site scripting attacks.
How do I fix CVE-2024-44120?
To fix CVE-2024-44120, you should apply the latest security patches provided by SAP for the NetWeaver Enterprise Portal.
What type of attack is CVE-2024-44120 associated with?
CVE-2024-44120 is associated with reflected cross-site scripting (XSS) attacks.
Who can be affected by CVE-2024-44120?
Any user of the SAP NetWeaver Enterprise Portal who clicks on a malicious URL could be affected by CVE-2024-44120.
Is authentication required to exploit CVE-2024-44120?
No, CVE-2024-44120 can be exploited by unauthenticated attackers who trick victims into clicking a crafted URL.