Cross-Site Scripting Vulnerability in SAP Web Dispatcher and Internet Communication Manager
CVE-2022-27656

6.1MEDIUM

Summary

The SAP Web Dispatcher and Internet Communication Manager (ICM) possess a security vulnerability where the web administration user interface fails to adequately encode user-controlled inputs. This shortfall allows attackers to exploit the system, leading to potential Cross-Site Scripting (XSS) attacks that can compromise sensitive data, redirect users, or execute arbitrary scripts within the context of the user's session.

Affected Version(s)

SAP NetWeaver AS for ABAP and Java (ICM Administration UI) KRNL64NUC 7.22

SAP NetWeaver AS for ABAP and Java (ICM Administration UI) 7.22EXT

SAP NetWeaver AS for ABAP and Java (ICM Administration UI) 7.49

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.