CVE-2024-33002

Document Service handler (obsolete) in Data Provisioning Service does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability with low impact on Confidentiality and Integrity of the application.
Configurations

No configuration.

History

21 Nov 2024, 09:16

Type Values Removed Values Added
Summary
  • (es) El controlador del servicio de documentos (obsoleto) en Data Provisioning Service no codifica suficientemente las entradas controladas por el usuario, lo que genera una vulnerabilidad de Cross Site Scripting (XSS) con bajo impacto en la confidencialidad y la integridad de la aplicación.
References () https://me.sap.com/notes/3460772 - () https://me.sap.com/notes/3460772 -
References () https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html - () https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html -

14 May 2024, 16:17

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-14 16:17

Updated : 2024-11-21 09:16


NVD link : CVE-2024-33002

Mitre link : CVE-2024-33002

CVE.ORG link : CVE-2024-33002


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')