SAP Cloud Connector, version - 2.0, does not sufficiently encode user-controlled inputs, allowing an attacker with Administrator rights, to include malicious codes that get stored in the database, and when accessed, could be executed in the application, resulting in Stored Cross-Site Scripting.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:NSap Cloud Connector
APPSap2.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
Related vulnerabilities
CVE-2021-33695CRITICAL9.1PL ✓same product
SAP Cloud Connector: niewystarczająca walidacja certyfikatu TLS
CVE-2019-0247CRITICAL9.8PL ✓same product
SAP Cloud Connector – wstrzyknięcie kodu (code injection) przed wersją 2.11.3
CVE-2019-0246CRITICAL9.8PL ✓same product
SAP Cloud Connector: brak uwierzytelnienia dla krytycznych funkcji
CVE-2024-25642HIGH7.4same product
Due to improper validation of certificate in SAP Cloud Connector - version 2.0, attacker can impersonate the g...
CVE-2021-33692HIGH7.5same product
SAP Cloud Connector, version - 2.0, allows the upload of zip files as backup. This backup file can be tricked ...