Vulnerability CVE-2024-34685


Published: 2024-07-09

Description:
Due to weak encoding of user-controlled input in
SAP NetWeaver Knowledge Management XMLEditor which allows malicious scripts can
be executed in the application, potentially leading to a Cross-Site Scripting
(XSS) vulnerability. This has no impact on the availability of the application
but it has a low impact on its confidentiality and integrity.

Type:

CWE-79

(Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'))

 References:
https://url.sap/sapsecuritypatchday
https://me.sap.com/notes/3468681

Copyright 2026, cxsecurity.com

 

Back to Top