Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal
CVE-2023-33985

6.1MEDIUM

Key Information:

Vendor
SAP
Vendor
CVE Published:
13 June 2023

Summary

SAP NetWeaver Enterprise Portal - version 7.50, does not sufficiently encode user-controlled inputs over the network, resulting in reflected Cross-Site Scripting (XSS) vulnerability, therefore changing the scope of the attack. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality and integrity of the application.

Affected Version(s)

SAP NetWeaver Enterprise Portal 7.50

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.