CVE-2022-29618
6.1MEDIUM
Key Information:
- Vendor
- SAP
- Vendor
- CVE Published:
- 14 June 2022
Summary
Due to insufficient input validation, SAP NetWeaver Development Infrastructure (Design Time Repository) - versions 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to inject script into the URL and execute code in the user’s browser. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality and integrity of the application.
Affected Version(s)
SAP NetWeaver Development Infrastructure (Design Time Repository) 7.30
SAP NetWeaver Development Infrastructure (Design Time Repository) 7.31
SAP NetWeaver Development Infrastructure (Design Time Repository) 7.40
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved