// For flags

CVE-2022-41266

 

Severity Score

6.1
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Due to a lack of proper input validation, SAP Commerce Webservices 2.0 (Swagger UI) - versions 1905, 2005, 2105, 2011, 2205, allows malicious inputs from untrusted sources, which can be leveraged by an attacker to execute a DOM Cross-Site Scripting (XSS) attack.  As a result, an attacker may be able to steal user tokens and achieve a full account takeover including access to administrative tools in SAP Commerce.

Debido a la falta de una validación de entrada adecuada, SAP Commerce Webservices 2.0 (Swagger UI): versiones 1905, 2005, 2105, 2011, 2205, permite entradas maliciosas de fuentes no confiables, que un atacante puede aprovechar para ejecutar un ataque de cross site scripting DOM (XSS). Como resultado, un atacante puede robar tokens de usuario y lograr el control total de la cuenta, incluido el acceso a herramientas administrativas en SAP Commerce.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
High
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2022-09-21 CVE Reserved
  • 2022-12-13 CVE Published
  • 2024-07-05 EPSS Updated
  • 2024-08-03 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Sap
Search vendor "Sap"
Commerce Webservices 2.0
Search vendor "Sap" for product "Commerce Webservices 2.0"
1905
Search vendor "Sap" for product "Commerce Webservices 2.0" and version "1905"
-
Affected
Sap
Search vendor "Sap"
Commerce Webservices 2.0
Search vendor "Sap" for product "Commerce Webservices 2.0"
2005
Search vendor "Sap" for product "Commerce Webservices 2.0" and version "2005"
-
Affected
Sap
Search vendor "Sap"
Commerce Webservices 2.0
Search vendor "Sap" for product "Commerce Webservices 2.0"
2011
Search vendor "Sap" for product "Commerce Webservices 2.0" and version "2011"
-
Affected
Sap
Search vendor "Sap"
Commerce Webservices 2.0
Search vendor "Sap" for product "Commerce Webservices 2.0"
2105
Search vendor "Sap" for product "Commerce Webservices 2.0" and version "2105"
-
Affected
Sap
Search vendor "Sap"
Commerce Webservices 2.0
Search vendor "Sap" for product "Commerce Webservices 2.0"
2205
Search vendor "Sap" for product "Commerce Webservices 2.0" and version "2205"
-
Affected