Reflected Cross-Site Scripting Vulnerability in SAP NetWeaver Enterprise Portal
CVE-2022-35170
6.1MEDIUM
What is CVE-2022-35170?
SAP NetWeaver Enterprise Portal versions 7.10 through 7.50 exhibit a reflected Cross-Site Scripting (XSS) vulnerability due to insufficient encoding of user-controlled inputs transmitted over the network. Attackers can exploit this flaw to manipulate the application's behavior, leading to potential unauthorized access or malicious script execution. As a result, while the impact on data confidentiality and integrity is limited, it poses a risk to users interacting with the portal, necessitating prompt assessment and mitigation.
Affected Version(s)
SAP NetWeaver Enterprise Portal 7.10
SAP NetWeaver Enterprise Portal 7.11
SAP NetWeaver Enterprise Portal 7.20