SAP NWBC for HTML Vulnerable to Cross-Site Scripting (XSS) Attacks
CVE-2024-22128
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 13 February 2024
What is CVE-2024-22128?
SAP NWBC for HTML - versions SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, SAP_UI 758, SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. An unauthenticated attacker can inject malicious javascript to cause limited impact to confidentiality and integrity of the application data after successful exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SAP NetWeaver Business Client for HTML SAP_UI 754
SAP NetWeaver Business Client for HTML SAP_UI 755
SAP NetWeaver Business Client for HTML SAP_UI 756
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved