CVE-2024-37178

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
11/06/2024
Last modified:
11/06/2024

Description

SAP Financial Consolidation does not<br /> sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting<br /> (XSS) vulnerability. These endpoints are exposed over the network. The<br /> vulnerability can exploit resources beyond the vulnerable component. On<br /> successful exploitation, an attacker can cause limited impact to<br /> confidentiality of the application.