Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-56965
HistoryJul 15, 2022 - 12:00 a.m.

SAP NetWeaver Portal Cross-Site Scripting Vulnerability (CNVD-2022-56965)

2022-07-1500:00:00
China National Vulnerability Database
www.cnvd.org.cn
22
sap netweaver
cross-site scripting
vulnerability
user input
authentication

EPSS

0.001

Percentile

44.7%

SAP NetWeaver Portal is a component of the SAP NetWeaver architecture from SAP Germany. cross-site scripting vulnerabilities exist in SAP NetWeaver Portal versions 7.30, 7.31, 7.40 and 7.50, which stem from a failure to adequately validate user-controlled input. An attacker could exploit the vulnerability to execute arbitrary scripting code that could lead to the theft or modification of a user’s authentication information, such as data related to the user’s current session.

EPSS

0.001

Percentile

44.7%

Related for CNVD-2022-56965