Описание
SAP Business Planning and Consolidation, versions - 750, 751, 752, 753, 754, 755, 810, 100, 200, can be abused by an attacker, allowing them to modify displayed application content without authorization, and to potentially obtain authentication information from other legitimate users, leading to Cross Site Scripting.
Ссылки
- Permissions Required
- Vendor Advisory
- Permissions Required
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:sap:business_planning_and_consolidation:100:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_planning_and_consolidation:200:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_planning_and_consolidation:750:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_planning_and_consolidation:751:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_planning_and_consolidation:752:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_planning_and_consolidation:753:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_planning_and_consolidation:754:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_planning_and_consolidation:755:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_planning_and_consolidation:810:*:*:*:*:*:*:*
EPSS
Процентиль: 59%
0.00384
Низкий
5.4 Medium
CVSS3
5.4 Medium
CVSS3
3.5 Low
CVSS2
Дефекты
CWE-79
Связанные уязвимости
github
больше 3 лет назад
SAP Business Planning and Consolidation, versions - 750, 751, 752, 753, 754, 755, 810, 100, 200, can be abused by an attacker, allowing them to modify displayed application content without authorization, and to potentially obtain authentication information from other legitimate users, leading to Cross Site Scripting.
EPSS
Процентиль: 59%
0.00384
Низкий
5.4 Medium
CVSS3
5.4 Medium
CVSS3
3.5 Low
CVSS2
Дефекты
CWE-79