CVE-2024-39595: SAP Business Warehouse
Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.
SAP Business Warehouse - Business Planning and Simulation application does not sufficiently encode user-controlled inputs, resulting in Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability allows users to modify website content and on successful exploitation, an attacker can cause low impact to the confidentiality and integrity of the application.
Affected products
- SAP Business Warehouse: version 700 only; version 701 only; version 702 only; version 730 only; version 731 only; version 740 only; …
- SAP Business Warehouse Virtual Comp: version 701 only
Published 2024-07-09. Last modified 2026-06-17.