NA

CVE-2024-27902

Published: 12/03/2024 Updated: 12/03/2024

Vulnerability Summary

Applications based on SAP GUI for HTML in SAP NetWeaver AS ABAP - versions 7.89, 7.93, do not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. A successful attack can allow a malicious malicious user to access and modify data through their ability to execute code in a user’s browser. There is no impact on the availability of the system