CVE-2024-42378: SAP SE SAP s/4hana Eprocurement
Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.
Due to weak encoding of user-controlled inputs, eProcurement on SAP S/4HANA allows malicious scripts to be executed in the application, potentially leading to a Reflected Cross-Site Scripting (XSS) vulnerability. This has no impact on the availability of the application, but it can have some minor impact on its confidentiality and integrity.
Affected products
- SAP SE SAP s/4hana Eprocurement: version S4CORE 102 only; version S4CORE 103 only; version S4CORE 104 only; version S4CORE 105 only; version S4CORE 106 only; version S4CORE 107 only; …
Published 2024-09-10. Last modified 2026-06-17.