Medium severity6.5NVD Advisory· Published May 14, 2024· Updated Jun 17, 2026
CVE-2024-34687
CVE-2024-34687
Description
SAP NetWeaver Application Server for ABAP and ABAP Platform do not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. An attacker can control code that is executed within a user’s browser, which could result in modification, deletion of data, including accessing or deleting files, or stealing session cookies which an attacker could use to hijack a user’s session. Hence, this could have impact on Confidentiality, Integrity and Availability of the system.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
19cpe:2.3:a:sap:sap_basis:700:*:*:*:*:*:*:*+ 15 more
- cpe:2.3:a:sap:sap_basis:700:*:*:*:*:*:*:*
- cpe:2.3:a:sap:sap_basis:701:*:*:*:*:*:*:*
- cpe:2.3:a:sap:sap_basis:702:*:*:*:*:*:*:*
- cpe:2.3:a:sap:sap_basis:731:*:*:*:*:*:*:*
- cpe:2.3:a:sap:sap_basis:740:*:*:*:*:*:*:*
- cpe:2.3:a:sap:sap_basis:750:*:*:*:*:*:*:*
- cpe:2.3:a:sap:sap_basis:751:*:*:*:*:*:*:*
- cpe:2.3:a:sap:sap_basis:752:*:*:*:*:*:*:*
- cpe:2.3:a:sap:sap_basis:753:*:*:*:*:*:*:*
- cpe:2.3:a:sap:sap_basis:754:*:*:*:*:*:*:*
- cpe:2.3:a:sap:sap_basis:755:*:*:*:*:*:*:*
- cpe:2.3:a:sap:sap_basis:756:*:*:*:*:*:*:*
- cpe:2.3:a:sap:sap_basis:757:*:*:*:*:*:*:*
- cpe:2.3:a:sap:sap_basis:758:*:*:*:*:*:*:*
- cpe:2.3:a:sap:sap_basis:795:*:*:*:*:*:*:*
- cpe:2.3:a:sap:sap_basis:796:*:*:*:*:*:*:*
- Range: SAP_BASIS 700
Patches
Vulnerability mechanics
References
2- support.sap.com/en/my-support/knowledge-base/security-notes-news.htmlnvdPatch
- me.sap.com/notes/3448445nvdPermissions Required
News mentions
0No linked articles in our index yet.