CVE-2024-37178
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
11/06/2024
Last modified:
11/06/2024
Description
SAP Financial Consolidation does not<br />
sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting<br />
(XSS) vulnerability. These endpoints are exposed over the network. The<br />
vulnerability can exploit resources beyond the vulnerable component. On<br />
successful exploitation, an attacker can cause limited impact to<br />
confidentiality of the application.
Impact
Base Score 3.x
5.00
Severity 3.x
MEDIUM



