The SAP Application Interface (Message Dashboard) - versions AIF 703, AIFX 702, S4CORE 100, 101, SAP_BASIS 755, 756, SAP_ABA 75C, 75D, 75E, application allows the usage HTML tags. An authorized attacker can use some of the basic HTML codes such as heading, basic formatting and lists, then an attacker can inject images from the foreign domains. After successful exploitations, an attacker can cause limited impact on the confidentiality and integrity of the application.
References
Link | Resource |
---|---|
https://launchpad.support.sap.com/#/notes/3113349 | Permissions Required |
https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
18 Apr 2023, 01:54
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:sap:application_interface_framework:aifx_702:*:*:*:*:*:*:* cpe:2.3:a:sap:abap_platform:75c:*:*:*:*:*:*:* cpe:2.3:a:sap:s4core:101:*:*:*:*:*:*:* cpe:2.3:a:sap:s4core:100:*:*:*:*:*:*:* cpe:2.3:a:sap:abap_platform:75e:*:*:*:*:*:*:* cpe:2.3:a:sap:application_interface_framework:aif_703:*:*:*:*:*:*:* cpe:2.3:a:sap:abap_platform:75d:*:*:*:*:*:*:* cpe:2.3:a:sap:basis:755:*:*:*:*:*:*:* cpe:2.3:a:sap:basis:756:*:*:*:*:*:*:* |
|
CWE | CWE-79 | |
First Time |
Sap basis
Sap s4core Sap Sap application Interface Framework Sap abap Platform |
|
References | (MISC) https://launchpad.support.sap.com/#/notes/3113349 - Permissions Required | |
References | (MISC) https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html - Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.4 |
11 Apr 2023, 04:16
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-04-11 04:16
Updated : 2023-04-18 01:54
NVD link : CVE-2023-29110
Mitre link : CVE-2023-29110
JSON object : View
Products Affected
sap
- application_interface_framework
- basis
- abap_platform
- s4core
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')