CVE-2023-29110

The SAP Application Interface (Message Dashboard) - versions AIF 703, AIFX 702, S4CORE 100, 101, SAP_BASIS 755, 756, SAP_ABA 75C, 75D, 75E, application allows the usage HTML tags. An authorized attacker can use some of the basic HTML codes such as heading, basic formatting and lists, then an attacker can inject images from the foreign domains. After successful exploitations, an attacker can cause limited impact on the confidentiality and integrity of the application.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sap:abap_platform:75c:*:*:*:*:*:*:*
cpe:2.3:a:sap:abap_platform:75d:*:*:*:*:*:*:*
cpe:2.3:a:sap:abap_platform:75e:*:*:*:*:*:*:*
cpe:2.3:a:sap:application_interface_framework:aif_703:*:*:*:*:*:*:*
cpe:2.3:a:sap:application_interface_framework:aifx_702:*:*:*:*:*:*:*
cpe:2.3:a:sap:basis:755:*:*:*:*:*:*:*
cpe:2.3:a:sap:basis:756:*:*:*:*:*:*:*
cpe:2.3:a:sap:s4core:100:*:*:*:*:*:*:*
cpe:2.3:a:sap:s4core:101:*:*:*:*:*:*:*

History

18 Apr 2023, 01:54

Type Values Removed Values Added
CWE CWE-80 CWE-79
References (MISC) https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html - (MISC) https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html - Vendor Advisory
References (MISC) https://launchpad.support.sap.com/#/notes/3113349 - (MISC) https://launchpad.support.sap.com/#/notes/3113349 - Permissions Required
First Time Sap abap Platform
Sap application Interface Framework
Sap
Sap basis
Sap s4core
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
CPE cpe:2.3:a:sap:s4core:100:*:*:*:*:*:*:*
cpe:2.3:a:sap:abap_platform:75c:*:*:*:*:*:*:*
cpe:2.3:a:sap:application_interface_framework:aifx_702:*:*:*:*:*:*:*
cpe:2.3:a:sap:abap_platform:75e:*:*:*:*:*:*:*
cpe:2.3:a:sap:abap_platform:75d:*:*:*:*:*:*:*
cpe:2.3:a:sap:application_interface_framework:aif_703:*:*:*:*:*:*:*
cpe:2.3:a:sap:basis:755:*:*:*:*:*:*:*
cpe:2.3:a:sap:s4core:101:*:*:*:*:*:*:*
cpe:2.3:a:sap:basis:756:*:*:*:*:*:*:*

11 Apr 2023, 04:16

Type Values Removed Values Added
New CVE

Information

Published : 2023-04-11 04:16

Updated : 2023-12-10 15:01


NVD link : CVE-2023-29110

Mitre link : CVE-2023-29110

CVE.ORG link : CVE-2023-29110


JSON object : View

Products Affected

sap

  • application_interface_framework
  • s4core
  • basis
  • abap_platform
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-80

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)