CVE-2024-37178
Cross-Site Scripting (XSS) vulnerabilities in SAP Financial Consolidation
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 5EPSS 0.3%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
11 jun 2024Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
SAP Financial Consolidation does not
sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting
(XSS) vulnerability. These endpoints are exposed over the network. The
vulnerability can exploit resources beyond the vulnerable component. On
successful exploitation, an attacker can cause limited impact to
confidentiality of the application.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Productos afectados
SAP_SE · SAP Financial Consolidation¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →