CVE-2022-35227
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in SAP NW EP (WPC) - versions 7.30, 7.31, 7.40, 7.50, which does not sufficiently validate user-controlled input, allows a remote attacker to conduct a Cross-Site (XSS) scripting attack. A successful exploit could allow the attacker to execute arbitrary script code which could lead to stealing or modifying of authentication information of the user, such as data relating to his or her current session.
Una vulnerabilidad en SAP NW EP (WPC) - versiones 7.30, 7.31, 7.40, 7.50, que no comprueba suficientemente la entrada controlada por el usuario, permite a un atacante remoto conducir un ataque de tipo Cross-Site scripting (XSS). Una explotación con éxito podría permitir al atacante ejecutar código de script arbitrario que podría conllevar a el robo o la modificación de la información de autenticación del usuario, como los datos relativos a su sesión actual
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-07-05 CVE Reserved
- 2022-07-12 CVE Published
- 2024-02-02 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html | 2022-07-20 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Sap Search vendor "Sap" | Netweaver Enterprise Portal Search vendor "Sap" for product "Netweaver Enterprise Portal" | 7.30 Search vendor "Sap" for product "Netweaver Enterprise Portal" and version "7.30" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Netweaver Enterprise Portal Search vendor "Sap" for product "Netweaver Enterprise Portal" | 7.31 Search vendor "Sap" for product "Netweaver Enterprise Portal" and version "7.31" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Netweaver Enterprise Portal Search vendor "Sap" for product "Netweaver Enterprise Portal" | 7.40 Search vendor "Sap" for product "Netweaver Enterprise Portal" and version "7.40" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Netweaver Enterprise Portal Search vendor "Sap" for product "Netweaver Enterprise Portal" | 7.50 Search vendor "Sap" for product "Netweaver Enterprise Portal" and version "7.50" | - |
Affected
|