CVE-2024-34687 is a critical Cross-Site Scripting (XSS) vulnerability affecting SAP NetWeaver Application Server for ABAP and ABAP Platform, stemming from insufficient encoding of user-controlled inputs. With a CVSS score of 9.0, this vulnerability allows an attacker to execute arbitrary code in a user's browser, potentially leading to high impact on confidentiality, integrity, and availability through data modification, deletion, file access, or session hijacking. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion with 10 mentions, indicating awareness among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
700CPE matchmatch criteria | cpe:2.3:a:sap:sap_basis:700:*:*:*:*:*:*:* | ||
701CPE matchmatch criteria | cpe:2.3:a:sap:sap_basis:701:*:*:*:*:*:*:* | ||
702CPE matchmatch criteria | cpe:2.3:a:sap:sap_basis:702:*:*:*:*:*:*:* | ||
731CPE matchmatch criteria | cpe:2.3:a:sap:sap_basis:731:*:*:*:*:*:*:* | ||
740CPE matchmatch criteria | cpe:2.3:a:sap:sap_basis:740:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.6 Bluesky, 0.3 Mastodon, and 1.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.