SAP Business Warehouse - Business Planning and Simulation application does not sufficiently encode user-controlled inputs, resulting in Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability allows users to modify website content and on successful exploitation, an attacker can cause low impact to the confidentiality and integrity of the application.
History

Tue, 28 Oct 2025 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Sap
Sap business Warehouse
Sap business Warehouse Virtual Comp
CPEs cpe:2.3:a:sap:business_warehouse:700:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_warehouse:701:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_warehouse:702:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_warehouse:730:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_warehouse:731:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_warehouse:740:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_warehouse:750:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_warehouse:751:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_warehouse:752:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_warehouse:753:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_warehouse:754:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_warehouse:755:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_warehouse:756:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_warehouse:757:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_warehouse:758:*:*:*:*:*:*:*
cpe:2.3:a:sap:business_warehouse_virtual_comp:701:*:*:*:*:*:*:*
Vendors & Products Sap
Sap business Warehouse
Sap business Warehouse Virtual Comp

cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published: 2024-07-09T04:13:49.560Z

Updated: 2024-08-02T04:26:16.023Z

Reserved: 2024-06-26T09:58:24.095Z

Link: CVE-2024-39595

cve-icon Vulnrichment

Updated: 2024-07-09T14:54:00.406Z

cve-icon NVD

Status : Analyzed

Published: 2024-07-09T05:15:12.507

Modified: 2025-10-28T18:41:39.603

Link: CVE-2024-39595

cve-icon Redhat

No data.