CVE-2022-29618
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Due to insufficient input validation, SAP NetWeaver Development Infrastructure (Design Time Repository) - versions 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to inject script into the URL and execute code in the user’s browser. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality and integrity of the application.
Debido a una insuficiente comprobación de entrada, SAP NetWeaver Development Infrastructure (Design Time Repository) - versiones 7.30, 7.31, 7.40, 7.50, permite a un atacante no autenticado inyectar un script en la URL y ejecutar código en el navegador del usuario. Si se explota con éxito, un atacante puede ver o modificar información causando un impacto limitado en la confidencialidad e integridad de la aplicación
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-04-25 CVE Reserved
- 2022-06-14 CVE Published
- 2024-01-05 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html | 2022-06-24 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Sap Search vendor "Sap" | Netweaver Development Infrastructure Search vendor "Sap" for product "Netweaver Development Infrastructure" | 7.30 Search vendor "Sap" for product "Netweaver Development Infrastructure" and version "7.30" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Netweaver Development Infrastructure Search vendor "Sap" for product "Netweaver Development Infrastructure" | 7.31 Search vendor "Sap" for product "Netweaver Development Infrastructure" and version "7.31" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Netweaver Development Infrastructure Search vendor "Sap" for product "Netweaver Development Infrastructure" | 7.40 Search vendor "Sap" for product "Netweaver Development Infrastructure" and version "7.40" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Netweaver Development Infrastructure Search vendor "Sap" for product "Netweaver Development Infrastructure" | 7.50 Search vendor "Sap" for product "Netweaver Development Infrastructure" and version "7.50" | - |
Affected
|