CVE-2024-39595

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
09/07/2024
Last modified:
28/10/2025

Description

SAP Business Warehouse - Business Planning and<br /> Simulation application does not sufficiently encode user-controlled inputs,<br /> resulting in Stored Cross-Site Scripting (XSS) vulnerability. This<br /> vulnerability allows users to modify website content and on successful<br /> exploitation, an attacker can cause low impact to the confidentiality and<br /> integrity of the application.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sap:business_warehouse:700:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_warehouse:701:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_warehouse:702:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_warehouse:730:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_warehouse:731:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_warehouse:740:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_warehouse:750:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_warehouse:751:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_warehouse:752:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_warehouse:753:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_warehouse:754:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_warehouse:755:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_warehouse:756:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_warehouse:757:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_warehouse:758:*:*:*:*:*:*:*