SAP CRM WebClient UI Vulnerability Allows Unauthorized Access to Victim's Browser
CVE-2024-34686
6.1MEDIUM
Summary
Due to insufficient input validation, SAP CRM WebClient UI allows an unauthenticated attacker to craft a URL link which embeds a malicious script. When a victim clicks on this link, the script will be executed in the victim's browser giving the attacker the ability to access and/or modify information with no effect on availability of the application.
Affected Version(s)
SAP CRM WebClient UI S4FND 102
SAP CRM WebClient UI 103
SAP CRM WebClient UI 104
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved