Cross-Site Scripting Vulnerability in SAP Web Dispatcher and Internet Communication Manager
CVE-2022-27656
6.1MEDIUM
Key Information:
- Vendor
SAP
- Status
- Vendor
- CVE Published:
- 11 May 2022
What is CVE-2022-27656?
The SAP Web Dispatcher and Internet Communication Manager (ICM) possess a security vulnerability where the web administration user interface fails to adequately encode user-controlled inputs. This shortfall allows attackers to exploit the system, leading to potential Cross-Site Scripting (XSS) attacks that can compromise sensitive data, redirect users, or execute arbitrary scripts within the context of the user's session.
Affected Version(s)
SAP NetWeaver AS for ABAP and Java (ICM Administration UI) KRNL64NUC 7.22
SAP NetWeaver AS for ABAP and Java (ICM Administration UI) 7.22EXT
SAP NetWeaver AS for ABAP and Java (ICM Administration UI) 7.49