CVE-2024-39595
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
09/07/2024
Last modified:
09/07/2024
Description
SAP Business Warehouse - Business Planning and<br />
Simulation application does not sufficiently encode user-controlled inputs,<br />
resulting in Stored Cross-Site Scripting (XSS) vulnerability. This<br />
vulnerability allows users to modify website content and on successful<br />
exploitation, an attacker can cause low impact to the confidentiality and<br />
integrity of the application.
Impact
Base Score 3.x
5.40
Severity 3.x
MEDIUM