CVE-2024-45280: Cross-Site Scripting (XSS) Vulnerability in SAP NetWeaver AS Java (Logon Application)
Published Sep 10, 2024
·Updated
Due to insufficient encoding of user-controlled inputs, SAP NetWeaver AS Java allows malicious scripts to be executed in the login application. This has a limited impact on confidentiality and integrity of the application. There is no impact on availability.
Affected Software
1 affected component
SAP NetWeaver AS Java
Event History
Sep 10, 2024
CVE Published
via MITRE·04:31 AM
Data Sourced
via MITRE·04:31 AM
DescriptionSeverity
Data Sourced
via NVD·05:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-45280?
CVE-2024-45280 has a limited impact on confidentiality and integrity of the application.
2
How do I fix CVE-2024-45280?
To fix CVE-2024-45280, users should apply the security patches provided by SAP for NetWeaver AS Java.
3
What exploitation vector is associated with CVE-2024-45280?
CVE-2024-45280 allows for the execution of malicious scripts due to insufficient encoding of user-controlled inputs in the login application.
4
Who is affected by CVE-2024-45280?
CVE-2024-45280 affects users of SAP NetWeaver AS Java.
5
What is the nature of the vulnerability in CVE-2024-45280?
CVE-2024-45280 is a cross-site scripting (XSS) vulnerability due to improper handling of user inputs.