VYPR
Medium severity6.1NVD Advisory· Published Dec 12, 2023· Updated Jun 17, 2026

CVE-2023-49577

CVE-2023-49577

Description

The SAP HCM (SMART PAYE solution) - versions S4HCMCIE 100, SAP_HRCIE 600, SAP_HRCIE 604, SAP_HRCIE 608, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. After successful exploitation, an attacker can cause limited impact on confidentiality and integrity of the application.

Affected products

6
  • cpe:2.3:a:sap:human_capital_management:s4hcmcie_100:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:sap:human_capital_management:s4hcmcie_100:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:human_capital_management:sap_hrcie_600:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:human_capital_management:sap_hrcie_604:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:human_capital_management:sap_hrcie_608:*:*:*:*:*:*:*
  • SAP/HCM (SMART PAYE solution)llm-fuzzy2 versions
    S4HCMCIE 100, SAP_HRCIE 600, SAP_HRCIE 604, SAP_HRCIE 608+ 1 more
    • (no CPE)range: S4HCMCIE 100, SAP_HRCIE 600, SAP_HRCIE 604, SAP_HRCIE 608
    • (no CPE)range: S4HCMCIE 100

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.