SAP NetWeaver Knowledge Management XMLEditor which allows malicious scripts can
be executed in the application, potentially leading to a Cross-Site Scripting
(XSS) vulnerability. This has no impact on the availability of the application
but it has a low impact on its confidentiality and integrity.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-34984 | Due to weak encoding of user-controlled input in SAP NetWeaver Knowledge Management XMLEditor which allows malicious scripts can be executed in the application, potentially leading to a Cross-Site Scripting (XSS) vulnerability. This has no impact on the availability of the application but it has a low impact on its confidentiality and integrity. |
Thu, 29 Aug 2024 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sap
Sap netweaver Knowledge Management And Collaboration \(kmc-cm\) |
|
| CPEs | cpe:2.3:a:sap:netweaver_knowledge_management_and_collaboration_\(kmc-cm\):7.50:*:*:*:*:*:*:* | |
| Vendors & Products |
Sap
Sap netweaver Knowledge Management And Collaboration \(kmc-cm\) |
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2024-08-02T02:59:21.683Z
Reserved: 2024-05-07T05:46:11.657Z
Link: CVE-2024-34685
Updated: 2024-08-02T02:59:21.683Z
Status : Modified
Published: 2024-07-09T04:15:12.090
Modified: 2026-06-17T07:33:52.487
Link: CVE-2024-34685
No data.
OpenCVE Enrichment
No data.
-
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
EUVD