Under certain conditions, ABAP Online Community in SAP NetWeaver (SAP_BASIS version 7.40) and SAP S/4HANA (SAP_BASIS versions 7.50, 7.51, 7.52, 7.53, 7.54), does not sufficiently encode user-controlled inputs, resulting in Reflected Cross-Site Scripting (XSS) vulnerability.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
sap netweaver 7.40 |
||
sap s\\/4hana 7.50 |
||
sap s\\/4hana 7.51 |
||
sap s\\/4hana 7.52 |
||
sap s\\/4hana 7.53 |
||
sap s\\/4hana 7.54 |