Home

Description

SAP Financial Consolidation allows data to enter a Web application through an untrusted source. These endpoints are exposed over the network and it allows the user to modify the content from the web site. On successful exploitation, an attacker can cause significant impact to confidentiality and integrity of the application.

PUBLISHED Reserved 2024-06-04 | Published 2024-06-11 | Updated 2024-08-02 | Assigner sap




HIGH: 8.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

Problem types

CWE-79: Improper Neutralization of Input During Web Page Generation

Product status

Default status
unaffected

FINANCE 1010
affected

References

me.sap.com/notes/3457592

support.sap.com/...t/knowledge-base/security-notes-news.html

me.sap.com/notes/3457592

support.sap.com/...t/knowledge-base/security-notes-news.html

cve.org (CVE-2024-37177)

nvd.nist.gov (CVE-2024-37177)

Download JSON